Security
How Jobkore protects your account, clients, documents, and payments — with Stripe-backed processing, secure storage, and private client-facing links.
Last updated Sep 6, 2026
#Account Security
Your Jobkore account is protected by several layers of security:
- Password requirements — Passwords must be at least 8 characters and include an uppercase letter, a lowercase letter, and a number.
- Email verification — New accounts must verify their email address before they can use the app. Changing your email also requires verification.
- A code on a new device — the right password from a browser Jobkore does not recognise gets a six-digit code by email, not a session. See below.
- Google sign-in — You can sign in with your Google account instead of a password.
#Signing In on a New Device
Enter the right password from a browser Jobkore has not seen before and it does not sign you in. It emails you a six-digit code and asks for that instead. Type it and you are in.
That browser is then trusted for 90 days, so the password alone is enough on your own phone and your own laptop. Signing in with Google skips the code entirely — Google has already checked who you are.
It is a code rather than a link. A link tapped in your mail app opens in a different browser from the one you were signing in on, which would put you back where you started.
This is not two-factor authentication
Jobkore will never call it that, because it is not. Password reset goes to the same inbox the code goes to, so anyone holding your email already holds the account. What the code stops is somebody who has only your password — a reused one from a leak somewhere else, which is how most accounts are actually taken. That is the whole claim, and it is worth the ten seconds it costs you twice a year.
Confirming the changes that matter
Three actions ask for a fresh code even on a device you already trust: changing your email address, setting a password, and deleting your account. Those are the three that would turn a borrowed session into a permanent one, so a signed-in browser is not enough on its own.
Ordinary sign-out does not un-trust your devices — being asked for a code every time you come back to your own phone is not security, it is a tax. Resetting your password does, because that is the one action that means somebody else may have had access.
#Data Protection
All connections to Jobkore are encrypted, so your data is protected in transit between your device and Jobkore's servers. Uploaded files (photos, attachments, logos) are stored securely with time-limited access links — they can't be accessed by anyone without authorization.
#Payment Security
Online payments are processed through Stripe, an industry-leading payment processor. Jobkore never stores or has access to your clients' credit card numbers or bank account details. All payment data goes directly to Stripe's secure systems.
#Sessions
Login sessions last 7 days and expire on that schedule whether you are active or not — they are not extended by use. When you log out, your session is ended everywhere: every device you are signed in on is signed out at once, which is what you want after leaving yourself logged in on a shared laptop.
There is no two-factor authentication in Jobkore — no authenticator app, no SMS code, no security key. The email code above is a different and weaker thing, and Jobkore states that rather than leaving you to assume otherwise.