Applicant Tracking System
A secure, cloud-based Applicant Tracking System designed for public sector recruitment. The service supports end-to-end hiring, from job creation and advertising through application management, shortlisting, interviews, offers and onboarding, with configurable workflows, role-based access controls, and full GDPR compliance.
Features
- End-to-end recruitment workflow from job creation to onboarding
- Configurable application forms with conditional logic and document uploads
- Role-based access controls for recruiters, panel members, and administrators
- Secure candidate portal accessible on desktop and mobile browsers
- Structured shortlisting and scoring with configurable feedback forms
- Interview scheduling with calendar integration and automated notifications
- Offer management with configurable templates and approval workflows
- GDPR-compliant data handling with retention controls and audit logging
- Real-time operational reporting with export to Excel and CSV
- Cloud-hosted service with encrypted data at rest and in transit
Benefits
- Manage recruitment processes efficiently through a single secure platform
- Reduce administrative effort with configurable workflows and automation
- Improve hiring governance using role-based access and audit trails
- Enable faster shortlisting through structured scoring and evaluation tools
- Support consistent decision-making with standardised recruitment processes
- Provide candidates with clear, accessible application and status updates
- Minimise compliance risk through built-in GDPR and retention controls
- Save time scheduling interviews using automated notifications and calendars
- Increase transparency with real-time reporting and data exports
- Support remote recruitment teams with browser-based access anywhere
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 3 3 7 5 2 1 1 9 5 8 6 0 1 9
Contact
THE HIRE LAB
Maurice Buckley
Telephone: 00353876799154
Email: maurice@thehirelab.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is accessed via modern web browsers and requires an active internet connection. Planned maintenance is carried out outside standard business hours where possible and notified in advance. Support is provided during published support hours. The service is delivered as a standardised SaaS platform; customer-specific hosting models or on-premise deployments are not supported.
- System requirements
-
- Modern web browser supporting current HTML5 and JavaScript standards
- Reliable internet connection for secure, browser-based service access
- JavaScript enabled in the browser
- Cookies enabled for session management and security
- PDF reader for viewing generated documents and reports
- Email access for receiving system notifications and alerts
- Screen resolution suitable for standard desktop or tablet display
- Secure user authentication credentials issued by the service
- Up-to-date operating system supporting modern web browsers
- Assistive technologies supported for accessibility, including screen readers
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support queries are acknowledged within one business hour during standard support hours (Monday to Friday).
Outside these hours, including weekends and public holidays, queries are logged and responded to on the next business day, unless otherwise agreed under a specific support arrangement. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
The service is supported through a structured, tiered support model.
Level 1 Support is included within the standard service cost and provides email and ticket-based support for incident resolution, configuration guidance, and defect management during standard business hours (9–5 UK time, Monday to Friday).
Level 2 Support is provided by application specialists and is included where issues require deeper functional or configuration investigation. Escalation from Level 1 is managed internally and does not incur additional cost.
Level 3 Support is provided by senior engineers for complex technical issues, defects, or infrastructure-related incidents. This level is included for incident resolution within agreed service levels.
A named Account Manager is provided to manage service oversight, governance, and service reviews. A Technical Architect or cloud support engineer is available as part of escalation handling when required.
Optional onsite support, extended hours, or project-based technical consultancy can be provided by prior agreement and is charged separately. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported through a structured onboarding and enablement approach designed for public sector teams.
At service commencement, users receive guided onboarding, including environment setup, configuration support, and initial familiarisation with workflows and roles. Online training sessions are provided for administrators and key users, focusing on practical, day-to-day use of the service.
Instead of separate user manuals, the service includes in-application guidance, such as contextual info buttons, tooltips, and prompts embedded directly within screens to support users as they complete tasks. This reduces reliance on external documentation and supports intuitive adoption.
The service is further supported by Learn Now video tutorials, which provide short, task-based walkthroughs covering common actions and administrative functions. These videos are accessible on demand and can be reused for refresher training or onboarding new users.
Where required, onsite training can be provided by prior agreement and is charged separately. Ongoing assistance is available through standard support channels to support continued adoption and change. - Service documentation
- Yes
- Documentation formats
- Other
- Other documentation formats
-
- Learn Now video tutorials
- In-application contextual guidance (info buttons and prompts)
- End-of-contract data extraction
-
Prior to contract end, the supplier works with the buyer to agree a data extraction scope and timetable, ensuring continuity and compliance. Recruitment data—including job records, applications, candidate profiles, workflow status, and reports—can be exported in structured, commonly used formats such as CSV or Excel to support re-use or migration to another system.
Data extraction is carried out by authorised supplier personnel to ensure data integrity and security. Where required, multiple exports can be provided to reflect agreed cut-off dates. The buyer remains the data controller throughout the process.
Following successful data extraction and written confirmation from the buyer, the service environment is securely decommissioned in accordance with GDPR and retention obligations. Data is permanently deleted from live systems and backups after the agreed retention period.
The exit process is well established and has been successfully used across public-sector clients, ensuring a controlled, low-risk transition with full transparency and auditability. - End-of-contract process
-
At the end of the contract, the service is managed in accordance with the agreed Exit Strategy to ensure an orderly and low-risk transition.
Included in the contract price, the supplier will support contract close-out activities, including confirmation of contract end dates, coordination with the buyer, and standard data extraction in agreed formats (such as CSV or Excel). Access to the service continues until the contract end date, allowing the buyer to complete in-flight recruitment activity where required.
Following contract expiry and confirmation that data extraction has been completed, the service environment is securely decommissioned. All buyer data is deleted in line with GDPR obligations and agreed retention periods.
Additional costs may apply where the buyer requests non-standard exit support, such as extended access beyond the contract end date, additional or repeated data extracts, bespoke data transformations, or on-site support. Any such costs are agreed in advance and charged at published professional services rates.
The exit process is documented, predictable, and designed to minimise disruption to the buyer’s operations. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is designed to work on mobile devices using a responsive, browser-based interface. Core functions such as reviewing applications, completing shortlisting and scoring, viewing candidate details, and accessing notifications are available on mobile. Some administrative configuration and reporting functions are optimised for desktop use due to screen size and data complexity.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, browser-based web interface. It provides role-specific dashboards for recruiters, administrators, and panel members, presenting tasks, applications, and workflow status in a clear, structured layout. Navigation is menu-driven with consistent screen layouts, inline guidance, and contextual actions. The interface supports responsive design for use on desktop, tablet, and mobile devices, and includes accessibility features such as keyboard navigation, screen reader support, and adjustable text sizing.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The service interface has been tested against WCAG 2.2 AA criteria using a combination of automated and manual testing. Automated accessibility testing is carried out using industry-standard tools to identify issues such as colour contrast, heading structure, form labelling, and ARIA attributes.
Manual testing has been performed using screen readers (including NVDA and VoiceOver) to validate keyboard navigation, focus order, form interactions, error messaging, and dynamic content updates. Findings are logged, prioritised, and addressed as part of the regular quality assurance and release process. - API
- Yes
- What users can and can't do using the API
-
The service provides a secure, documented API to support integration with external systems. The API allows authorised users or systems to exchange data programmatically, subject to authentication and access controls.
Using the API, users can create and update recruitment data, including job records, vacancy status, candidate applications, and selected workflow events. The API also supports retrieval of structured data for reporting, integration with HR, identity, or assessment systems, and synchronisation of status updates.
Initial core service setup—such as configuration of workflows, forms, user roles, and permissions—is performed through the service’s administrative interface rather than via API. This ensures controlled governance and consistency.
The API is not intended for full system configuration or schema changes. Administrative functions such as creating new workflow stages, modifying scoring models, or altering security policies are restricted to the application interface.
API usage is subject to rate limits, versioning controls, and access scopes to ensure platform stability and security. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service supports extensive configuration-based customisation to align with organisational recruitment processes, without code changes.
Authorised administrators can customise recruitment workflows, including application stages, approval steps, shortlisting and interview processes. Application forms can be configured with custom fields, conditional logic, document uploads, and validation rules. Users can also customise email and document templates, scoring forms, and notification content.
User roles and permissions are configurable, allowing buyers to control access for recruiters, hiring managers, panel members, and third-party users. Branding elements such as logos, colours, and public-facing text can be adjusted to reflect organisational identity.
Customisation is carried out through secure, browser-based administrative screens. Changes take effect immediately or at defined points in the workflow, depending on configuration.
Only users with appropriate administrative permissions can make customisations, ensuring governance and auditability. Complex or organisation-wide configuration changes can be supported by the supplier by prior agreement.
Scaling
- Independence of resources
- The service is delivered as a multi-tenant SaaS platform with logical separation of customer data and workloads. Capacity is proactively monitored and scaled to maintain performance as demand fluctuates. Usage limits, background job controls, and performance monitoring are used to prevent individual customer activity from impacting others. The underlying cloud infrastructure is designed for high availability and resilience, ensuring consistent service performance across all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides a range of operational and usage metrics to support oversight and reporting. These include metrics on recruitment activity such as numbers of jobs, applications, shortlisting and interview outcomes, and time-to-hire indicators. System usage metrics are available, including user activity, workflow progression, and report generation. Service performance metrics, such as system availability and support ticket volumes, can also be provided to support service reviews and ongoing governance.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data through built-in reporting and administrative functions. Report-generated data can be exported directly by authorised users to Excel or CSV for operational and management purposes. For full contract exit or bulk data extraction, authorised supplier personnel perform structured data exports on behalf of the buyer to ensure security and data integrity. Export scope and timing are agreed in advance, and data is provided in commonly used formats such as Excel or CSV via secure transfer methods.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed for high availability and is delivered on resilient cloud infrastructure. The supplier guarantees 99.5% service availability, measured monthly, excluding planned maintenance and factors outside the supplier’s reasonable control.
Availability is monitored continuously, and performance is reviewed as part of regular service governance. If availability falls below the guaranteed level, service credits are applied in accordance with the agreed Service Level Agreement. Service credits are calculated as a percentage of the monthly service charge and are applied to future invoices.
Planned maintenance is scheduled outside core business hours wherever possible and is notified in advance. Full details of availability measurement, exclusions, and service credit application are provided within the contract documentation. - Approach to resilience
-
The service is designed with resilience as a core principle and is hosted on highly available cloud infrastructure. It operates across multiple, physically separate availability zones within the UK to protect against single points of failure. Infrastructure components are monitored continuously, with automated recovery mechanisms in place to maintain service continuity.
Data is stored on resilient, replicated storage with regular backups and tested recovery procedures. Application services are designed to tolerate component failure without service interruption where possible.
The underlying datacentre infrastructure is managed by AWS and includes resilient power, cooling, physical security, and environmental controls. Detailed architectural and resilience information can be provided to buyers on request, in line with security and assurance requirements. - Outage reporting
-
The service reports outages through clear, direct communication channels to ensure transparency and timely awareness.
There is no public status dashboard or outage reporting API. Service availability and incidents are monitored internally on a continuous basis.
In the event of a service outage or significant incident, email notifications are issued to nominated buyer contacts, providing details of the issue, current status, and expected resolution times where available. Updates are provided at appropriate intervals until service restoration is confirmed.
Outage information and incident summaries are also available through the service’s support ticketing system, allowing buyers to track progress and maintain an audit trail.
Post-incident reporting, including root cause analysis and corrective actions, can be provided on request as part of ongoing service governance and review processes.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted through role-based access controls and secure authentication mechanisms. Only authorised users with appropriate permissions can access administrative functions, configuration settings, or sensitive data. Access is granted on a least-privilege basis and reviewed regularly.
Support channels are similarly restricted. Only nominated customer contacts can raise or manage support tickets, and identity verification is applied where support requests involve sensitive information or account changes. Supplier support staff access is controlled, logged, and limited to the minimum required to resolve issues. All access and administrative actions are audited to support accountability and security oversight. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is managed through a defined internal framework aligned with recognised best practices and government cloud security principles. The approach includes documented security policies, role-based access controls, and clear ownership of security responsibilities. Regular risk assessments, vulnerability management, and annual external penetration testing are carried out to identify and address risks. Security considerations are embedded into the software development lifecycle, with change management, access reviews, and incident response procedures in place to support ongoing compliance and service resilience.
- Information security policies and processes
-
The organisation operates a set of documented information security policies and processes aligned with recognised best practice and government cloud security principles.
These policies cover areas including access control, data protection, secure software development, incident management, vulnerability management, backup and recovery, and supplier management. Policies are reviewed regularly and updated to reflect changes in risk, technology, or regulatory requirements.
Security responsibilities are clearly defined, with overall accountability held by senior management and day-to-day oversight managed by designated technical leads. Security incidents, risks, and compliance matters are reported through an internal escalation structure, ensuring visibility at management level.
Compliance with policies is supported through role-based access controls, mandatory use of secure development and operational practices, change management controls, and regular security reviews. External penetration testing and internal monitoring are used to validate that controls are operating effectively, and remediation actions are tracked to completion. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management are managed through defined internal processes aligned with operational security best practice. Service components are tracked through their lifecycle using version control, change records, and environment management controls. All changes are assessed for functional and security impact prior to implementation, including consideration of data protection, access controls, and service availability. Changes are tested in controlled environments before deployment, with rollback procedures in place. Security-related changes and incidents are reviewed and documented to support auditability and continuous improvement.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is handled through defined internal processes aligned with operational security best practice. Potential threats are assessed using a combination of automated scanning, external penetration testing, and ongoing risk review. Vulnerabilities are prioritised based on severity, exploitability, and potential impact. Patches and mitigations are deployed promptly in line with risk, with critical issues addressed as a priority and tested before release. Information on emerging threats is obtained from cloud provider advisories, trusted security sources, vulnerability databases, and penetration testing reports.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is performed through continuous system and application monitoring, log collection, and automated alerts to identify potential compromises such as unusual access patterns, errors, or service anomalies. Logs are reviewed and retained to support investigation and audit requirements. When a potential compromise is identified, it is assessed promptly, escalated in line with incident response procedures, and appropriate containment and remediation actions are taken. Incidents are prioritised by severity, with critical incidents responded to immediately during support hours and managed through to resolution with documented outcomes.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The organisation operates defined incident management processes to ensure timely and consistent response. Pre-defined procedures are in place for common events such as service outages, security incidents, and data protection issues. Users report incidents through email, phone, or the online ticketing system. Incidents are logged, prioritised, and managed in line with severity and impact. Updates are provided to users during incident resolution, and incident reports, including root cause and corrective actions, are supplied to buyers on request following resolution.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-