R1
R
ecruiter
1
For CandidatesFor AgenciesFor Enterprise
The hiring network you don't have to leave

Secure enough
for secrets.

Recruiting runs on networks that can read your messages. R1 can't. The offer, the counteroffer, the part you'd normally take to Signal — it stays here, end-to-end encrypted.

For CandidatesFor AgenciesFor Enterprise
AC
Acme · Senior Engineer
Direct message
On LinkedIn
Great call today — the team loved you.
Likewise. Excited about it.
What's the real ceiling on base?
“Let's move this to Signal.”
Stored readable · AI-scanned · subpoena-discoverable.

Every other network makes you leave. R1 doesn't.

PrivateClient-side only
ControlledYou own the keys
HumanNo intermediaries

Latest posts

News, market analyses and product updates from the R1 team.

View all
Market shiftEnterprise AI

AI Jobs Boom Bypasses Junior Workers: A Structural Shift in Talent Demand

ProductInfrastructure

Data Center Construction Surge Creates Local Friction Alongside AI-Driven Demand

Market shiftFintech

Banks Replace Lower-Value Roles With AI as Recent Graduates Face Hiring Challenges

RegulationEnterprise AI

Canada Unveils Ambitious AI Strategy Targeting 250,000 Jobs and 3% GDP Uplift

ProductCybersecurity

Anthropic Scales Mythos AI Access to 200 Glasswing Partners, Targeting Government and Financial Cybersecurity

View all intelligence
The broken default

How the world
shares candidates

Every ATS, every agency, every platform. This is what "state of the art" looks like.
01

Uncontrolled PDF Distribution

Recruiters reformat CVs into Word docs and email them. Files get forwarded infinitely. Zero access control. The candidate's PII lives on random laptops, inboxes, and Slack channels forever. Once sent, it's gone.

0%
Access Control
02

Portal Access Barriers

Greenhouse, Bullhorn, Vincere — they all require the hiring manager to create an account, navigate a dashboard, learn a UI. By the time they're onboarded, the candidate accepted somewhere else.

14d
Avg Onboarding
03

Static Candidate Portrayals

LinkedIn profiles are generic billboards. ATS portals show parsed resume data in card layouts. Nothing is tailored to the role. Nothing tells a story. The same CV goes to every company for every position.

1
Version for All
04

Disconnected Offline Files

A PDF is a static document the moment it's downloaded. No updates, no context, no way back to the source. The hiring manager prints it, scribbles notes in the margin, and throws it away after the meeting.

None
Update Loop
The R1 answer

Connect
Protocol

A single URL replaces the entire PDF-email-login-portal pipeline. Here's what it does.
Acme Corp
Senior Engineer

Alex Chen

Senior Engineer

Led the real-time sync engine rewrite at Linear, reducing p99 latency by 68%. Architected distributed event sourcing pipeline processing 2.4M events/day with zero data loss across 3 regions.

Experience

Staff Engineer — Real-time Systems
Linear
2022 — Present
ReactNode.jsDistributed SystemsCRDTsEvent SourcingAWSPostgreSQLKubernetes
  • Rewrote the sync engine from polling to CRDT-based real-time, cutting p99 from 1.2s to 380ms
  • Designed event sourcing pipeline handling 2.4M events/day across US, EU, APAC regions
Senior Engineer — Platform
Vercel
2019 — 2022
  • Built the edge function runtime serving 14B requests/month with sub-50ms cold starts

Skills

ReactNode.jsDistributed SystemsCRDTsEvent SourcingAWSPostgreSQLKubernetes
Acme CorpAlex Chen
Senior Engineer
Lisa Park

Alex looks strong. What's their availability?

2m ago

Available in 2 weeks. Also interviewing at Stripe — we should move fast.

1m ago
Lisa Park

Let's schedule for tomorrow. Can you confirm?

30s ago

Done. Calendar invite sent. I'll prep Alex tonight.

Just now
Type a message...
E2EE
R1
Connect
Honest comparison

R1 Connect

A live candidate page, backed by the R1 talent network.
Capability
R1
PDF / emailATS portalLinkedIn profile
Opens without an account
VariesVaries
Tailored to the role
ManualVaries—
Expiring shared access
—Varies—
Viewer limit for a shared link
—Varies—
Trust phrase for a new browser
———
Chat embedded on the candidate page
—Varies—
End-to-end encrypted embedded chat
—Not typical—
Key numbers highlighted automatically
ManualVaries—
PDF linking back to the live page
ManualVaries—
Offline copy
Varies—
Compare and rank candidates for a role
ManualVaries
Built-in candidate network
——
Network size
Growing——1.3B+

Message
Security

Private hiring conversations should stay private.

Recruiting platforms now hold some of the most sensitive professional data people share: resumes, work history, contact details, salary context, and conversations they expect to remain confidential. In 2025, reported recruiting-platform incidents put 100M+ applicant records and files at risk.

Sources: McHire researcher writeup, TalentHook / Cybernews, Foh&Boh / Cybernews, HireClick

100M+
Applicant records/files reportedly exposed or put at risk
Recruiting platforms, 2025
$10.22M
Average US breach cost
Source: IBM Cost of a Data Breach 2025, CyberScoop coverage
€1.2B
GDPR fines across surveyed European countries
Source: DLA Piper GDPR survey 2026
0
Readable plaintext message bodies in R1 protected E2EE chat stores
Source: R1 client-side encryption + strict server-side E2EE validation
See it happen
Your device
Plaintext, on your screen
AES-256-GCM · X25519
R1 servers
—
Everything R1 can see
Recipient device
Decrypted, for their eyes only
Awaiting trusted device

Encrypted on your device. R1 stores ciphertext. Only the recipient's device can read it.

What keeps happening
01

McHire

McDonald's franchisee hiring platform

A hiring chatbot used by McDonald's franchisees exposed a path to applicant data through basic access-control failures, including default credentials and an IDOR vulnerability. Researchers reported that up to 64 million applicant records could have been accessed.

Source: Ian Carroll + Sam Curry, WIRED
64M
Records potentially exposed
02

TalentHook

Applicant Tracking System Leak

A misconfigured Azure Blob container exposed nearly 26 million files, mostly resumes and CVs, with personal and professional details.

Source: Cybernews
26M
Files exposed
03

Foh&Boh

Hospitality and retail hiring platform

A publicly exposed AWS bucket contained 5.4 million files, largely resumes and CVs submitted through a hiring platform used by hospitality and retail brands.

Source: Cybernews
5.4M
Files exposed
04

HireClick

Resume platform breach

A misconfigured cloud bucket reportedly exposed 5.7 million resume files containing names, addresses, emails, phone numbers, and employment history.

Source: Daily Security Review
5.7M
Resumes exposed
Encryption comparison

What protects the message itself.

Protection
R1 protected chat
LinkedIn messagesTypical ATS messagingWhatsApp personal chats
Encrypted in transit with TLS
Messages encrypted end to end
——
Service cannot read message content
——
Keys unique to each device
——
Thread keys wrapped for each recipient device
——
Trusted key changes are detected
——
Append-only audit log of every device key change
——
Revoked devices stop receiving message keys
——
Cross-device recovery without exposing plaintext to the service
——
Unverified cross-party devices blocked before key delivery
———
Invalid encrypted envelopes rejected before storage
———
Realtime message alerts contain metadata only
———
Built in
—Not offered as a native protection

ATS refers to standard native messaging in Greenhouse, Lever, Bullhorn, iCIMS, and Workday. Third-party integrations are excluded.

Protections apply to message content. As with all end-to-end encryption, conversation metadata (participants and timestamps) is not message content. R1 uses per-thread keys wrapped to each verified device, fail-closed on key changes, with an append-only key-change log.

Under the hood

Technology
primitives

The cryptographic and systems primitives that make zero-friction secure sharing possible.

The link is the key

Every recruiter link is a one-time credential that belongs to a specific candidate and application. It expires on its own. No cookies, no sessions, no mystery tokens.

When the link dies, the access dies with it.

Only the right people can join

First viewer gets a server-generated 15-word connect phrase bound to their device. Subsequent access from new devices requires the phrase.

Too many wrong tries and the link locks them out.

You decide how far it spreads

You set a limit on how many unique people can hold the link at once. Once you hit that limit, no one else can join. The candidate controls the circle of trust.

The candidate controls the circle of trust.

Time-Bound Expiry

Links expire after a configurable duration. The countdown is visible to the holder. Expired links show a clean 'not found' state. No zombie data.

No stale data, no ghost access, no surprises.

Magic Token PDF

PDF downloads mint a one-time magic token embedded as a URL in the document. The offline artifact always points back to the live, controlled, interactive page.

The document never becomes a dead, uncontrolled file.

Real talk

Hiring managers can chat live on the recruiter page without jumping to Slack, email, or another tool. The conversation stays with the candidate, in context, where decisions happen.

E2E encrypted, no plaintext storage

AES-256-GCM + HKDF

Client-side AES-GCM keeps message content encrypted before it reaches the server. Supported chat stores add server-side AES-256-GCM at-rest encryption with per-thread HKDF-derived keys, so stored data remains ciphertext.

The server stores ciphertext, not message plaintext.

Sources: R1, NIST GCM, RFC 5869 HKDF

Per-Device Key Exchange

Every recipient device gets its own wrapped copy of the thread sender key, derived through X25519 key agreement and sealed with AES-256-GCM, without exposing message plaintext to the server. It sits in the same broad design family as modern secure messengers like Signal and WhatsApp.

One device, one wrap, one trust decision.

Sources: R1, RFC 7748 (X25519)

Redacted Realtime

Realtime events carry redacted metadata only, never message plaintext. Payloads identify the event, channel/scope, timestamps, and routing metadata so clients can re-fetch the encrypted message state from storage.

A compromised realtime listener may see that activity occurred and some routing metadata, but not the message body.

Per-Device Identity Keys

Each device gets its own cryptographic identity. Private keys stay local in IndexedDB, while the server only knows the public keys and who they belong to.

If a device is revoked, it is removed from future key access without signing the user out everywhere.

Sources: R1, RFC 7748, RFC 8032

Verified Recipient Enforcement

R1 checks device ownership, thread membership, and trust status before any wrapped sender key is stored or delivered.

Only verified devices get the keys.

Tofu Trust Verification

R1 remembers the first trusted fingerprint for each device using SHA-256. If that device's key changes later, the client blocks secure messaging instead of silently accepting the new key. This catches unexpected key changes after trust is established.

R1 pins device fingerprints on first trust.
The Bottom Line

R1 can't read your conversations. Not won't — can't.

The Problem

Most recruiting platforms were not built for end-to-end encrypted conversations. LinkedIn's own messaging docs describe server-side smart features, and 2025 showed how fragile recruiting data can be: one recruiting software exposure alone leaked nearly 26 million resumes through a misconfigured cloud container.

How R1 Is Different

R1 is built around end-to-end encryption. Message content is encrypted on your device before it reaches our servers and stored only as ciphertext. Because R1 cannot read it, it cannot be mined, profiled, or used to train AI models — a property of the architecture, not a promise.

  • Per-device identity keys with X25519 key exchange
  • Client-side AES-GCM message encryption, AES-256-GCM at-rest on supported stores
  • Per-thread keys, individually wrapped for each verified recipient device
  • Trust-on-first-use fingerprinting that blocks messaging if a device key changes
  • Verified-recipient enforcement before any thread key is delivered
  • Immediate device revocation — a removed device loses key access at once
  • An append-only, hash-chained log of every device-key change

Messages reach the recruiter and no one in between. Not even us. It's not a privacy policy — it's math.

Start sharing candidates securely today.

Whether you are an agency team scaling client operations or a candidate protecting your profile, R1 is built to serve your autonomy.

For Agencies & Teams

Deploy your secure recruiter portals.

Create roles, generate custom shares, live-chat with hiring managers, and capture every decision. No client login required, protected by Connect Protocol.

Explore Agency Platform
Request a demo
For Professionals

Own your candidate narrative.

Present your timeline in an interactive, controlled environment. Bind unique device fingerprints, limit the number of viewers, and prevent AI scraping.

Explore Candidate Features
Learn more
© 2026
R1
Home
For agenciesFor enterpriseFor candidatesCareersBlogAboutTermsPrivacy