Skip to main content

Help us improve the Digital Marketplace - send your feedback

THE HIRE LAB

Applicant Tracking System

A secure, cloud-based Applicant Tracking System designed for public sector recruitment. The service supports end-to-end hiring, from job creation and advertising through application management, shortlisting, interviews, offers and onboarding, with configurable workflows, role-based access controls, and full GDPR compliance.

Features

  • End-to-end recruitment workflow from job creation to onboarding
  • Configurable application forms with conditional logic and document uploads
  • Role-based access controls for recruiters, panel members, and administrators
  • Secure candidate portal accessible on desktop and mobile browsers
  • Structured shortlisting and scoring with configurable feedback forms
  • Interview scheduling with calendar integration and automated notifications
  • Offer management with configurable templates and approval workflows
  • GDPR-compliant data handling with retention controls and audit logging
  • Real-time operational reporting with export to Excel and CSV
  • Cloud-hosted service with encrypted data at rest and in transit

Benefits

  • Manage recruitment processes efficiently through a single secure platform
  • Reduce administrative effort with configurable workflows and automation
  • Improve hiring governance using role-based access and audit trails
  • Enable faster shortlisting through structured scoring and evaluation tools
  • Support consistent decision-making with standardised recruitment processes
  • Provide candidates with clear, accessible application and status updates
  • Minimise compliance risk through built-in GDPR and retention controls
  • Save time scheduling interviews using automated notifications and calendars
  • Increase transparency with real-time reporting and data exports
  • Support remote recruitment teams with browser-based access anywhere

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at maurice@thehirelab.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 3 3 7 5 2 1 1 9 5 8 6 0 1 9

Contact

THE HIRE LAB Maurice Buckley
Telephone: 00353876799154
Email: maurice@thehirelab.com

About your service

Service categories

Applications

Enterprise resource management

Human capital management

  • Talent Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service is accessed via modern web browsers and requires an active internet connection. Planned maintenance is carried out outside standard business hours where possible and notified in advance. Support is provided during published support hours. The service is delivered as a standardised SaaS platform; customer-specific hosting models or on-premise deployments are not supported.
System requirements
  • Modern web browser supporting current HTML5 and JavaScript standards
  • Reliable internet connection for secure, browser-based service access
  • JavaScript enabled in the browser
  • Cookies enabled for session management and security
  • PDF reader for viewing generated documents and reports
  • Email access for receiving system notifications and alerts
  • Screen resolution suitable for standard desktop or tablet display
  • Secure user authentication credentials issued by the service
  • Up-to-date operating system supporting modern web browsers
  • Assistive technologies supported for accessibility, including screen readers

User support

Email or online ticketing support
Yes
Support response times
Support queries are acknowledged within one business hour during standard support hours (Monday to Friday).
Outside these hours, including weekends and public holidays, queries are logged and responded to on the next business day, unless otherwise agreed under a specific support arrangement.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
The service is supported through a structured, tiered support model.

Level 1 Support is included within the standard service cost and provides email and ticket-based support for incident resolution, configuration guidance, and defect management during standard business hours (9–5 UK time, Monday to Friday).

Level 2 Support is provided by application specialists and is included where issues require deeper functional or configuration investigation. Escalation from Level 1 is managed internally and does not incur additional cost.

Level 3 Support is provided by senior engineers for complex technical issues, defects, or infrastructure-related incidents. This level is included for incident resolution within agreed service levels.

A named Account Manager is provided to manage service oversight, governance, and service reviews. A Technical Architect or cloud support engineer is available as part of escalation handling when required.

Optional onsite support, extended hours, or project-based technical consultancy can be provided by prior agreement and is charged separately.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Users are supported through a structured onboarding and enablement approach designed for public sector teams.

At service commencement, users receive guided onboarding, including environment setup, configuration support, and initial familiarisation with workflows and roles. Online training sessions are provided for administrators and key users, focusing on practical, day-to-day use of the service.

Instead of separate user manuals, the service includes in-application guidance, such as contextual info buttons, tooltips, and prompts embedded directly within screens to support users as they complete tasks. This reduces reliance on external documentation and supports intuitive adoption.

The service is further supported by Learn Now video tutorials, which provide short, task-based walkthroughs covering common actions and administrative functions. These videos are accessible on demand and can be reused for refresher training or onboarding new users.

Where required, onsite training can be provided by prior agreement and is charged separately. Ongoing assistance is available through standard support channels to support continued adoption and change.
Service documentation
Yes
Documentation formats
Other
Other documentation formats
  • Learn Now video tutorials
  • In-application contextual guidance (info buttons and prompts)
End-of-contract data extraction
Prior to contract end, the supplier works with the buyer to agree a data extraction scope and timetable, ensuring continuity and compliance. Recruitment data—including job records, applications, candidate profiles, workflow status, and reports—can be exported in structured, commonly used formats such as CSV or Excel to support re-use or migration to another system.

Data extraction is carried out by authorised supplier personnel to ensure data integrity and security. Where required, multiple exports can be provided to reflect agreed cut-off dates. The buyer remains the data controller throughout the process.

Following successful data extraction and written confirmation from the buyer, the service environment is securely decommissioned in accordance with GDPR and retention obligations. Data is permanently deleted from live systems and backups after the agreed retention period.

The exit process is well established and has been successfully used across public-sector clients, ensuring a controlled, low-risk transition with full transparency and auditability.
End-of-contract process
At the end of the contract, the service is managed in accordance with the agreed Exit Strategy to ensure an orderly and low-risk transition.

Included in the contract price, the supplier will support contract close-out activities, including confirmation of contract end dates, coordination with the buyer, and standard data extraction in agreed formats (such as CSV or Excel). Access to the service continues until the contract end date, allowing the buyer to complete in-flight recruitment activity where required.

Following contract expiry and confirmation that data extraction has been completed, the service environment is securely decommissioned. All buyer data is deleted in line with GDPR obligations and agreed retention periods.

Additional costs may apply where the buyer requests non-standard exit support, such as extended access beyond the contract end date, additional or repeated data extracts, bespoke data transformations, or on-site support. Any such costs are agreed in advance and charged at published professional services rates.

The exit process is documented, predictable, and designed to minimise disruption to the buyer’s operations.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is designed to work on mobile devices using a responsive, browser-based interface. Core functions such as reviewing applications, completing shortlisting and scoring, viewing candidate details, and accessing notifications are available on mobile. Some administrative configuration and reporting functions are optimised for desktop use due to screen size and data complexity.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, browser-based web interface. It provides role-specific dashboards for recruiters, administrators, and panel members, presenting tasks, applications, and workflow status in a clear, structured layout. Navigation is menu-driven with consistent screen layouts, inline guidance, and contextual actions. The interface supports responsive design for use on desktop, tablet, and mobile devices, and includes accessibility features such as keyboard navigation, screen reader support, and adjustable text sizing.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface has been tested against WCAG 2.2 AA criteria using a combination of automated and manual testing. Automated accessibility testing is carried out using industry-standard tools to identify issues such as colour contrast, heading structure, form labelling, and ARIA attributes.

Manual testing has been performed using screen readers (including NVDA and VoiceOver) to validate keyboard navigation, focus order, form interactions, error messaging, and dynamic content updates. Findings are logged, prioritised, and addressed as part of the regular quality assurance and release process.
API
Yes
What users can and can't do using the API
The service provides a secure, documented API to support integration with external systems. The API allows authorised users or systems to exchange data programmatically, subject to authentication and access controls.

Using the API, users can create and update recruitment data, including job records, vacancy status, candidate applications, and selected workflow events. The API also supports retrieval of structured data for reporting, integration with HR, identity, or assessment systems, and synchronisation of status updates.

Initial core service setup—such as configuration of workflows, forms, user roles, and permissions—is performed through the service’s administrative interface rather than via API. This ensures controlled governance and consistency.

The API is not intended for full system configuration or schema changes. Administrative functions such as creating new workflow stages, modifying scoring models, or altering security policies are restricted to the application interface.

API usage is subject to rate limits, versioning controls, and access scopes to ensure platform stability and security.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service supports extensive configuration-based customisation to align with organisational recruitment processes, without code changes.

Authorised administrators can customise recruitment workflows, including application stages, approval steps, shortlisting and interview processes. Application forms can be configured with custom fields, conditional logic, document uploads, and validation rules. Users can also customise email and document templates, scoring forms, and notification content.

User roles and permissions are configurable, allowing buyers to control access for recruiters, hiring managers, panel members, and third-party users. Branding elements such as logos, colours, and public-facing text can be adjusted to reflect organisational identity.

Customisation is carried out through secure, browser-based administrative screens. Changes take effect immediately or at defined points in the workflow, depending on configuration.

Only users with appropriate administrative permissions can make customisations, ensuring governance and auditability. Complex or organisation-wide configuration changes can be supported by the supplier by prior agreement.

Scaling

Independence of resources
The service is delivered as a multi-tenant SaaS platform with logical separation of customer data and workloads. Capacity is proactively monitored and scaled to maintain performance as demand fluctuates. Usage limits, background job controls, and performance monitoring are used to prevent individual customer activity from impacting others. The underlying cloud infrastructure is designed for high availability and resilience, ensuring consistent service performance across all users.

Analytics

Service usage metrics
Yes
Metrics types
The service provides a range of operational and usage metrics to support oversight and reporting. These include metrics on recruitment activity such as numbers of jobs, applications, shortlisting and interview outcomes, and time-to-hire indicators. System usage metrics are available, including user activity, workflow progression, and report generation. Service performance metrics, such as system availability and support ticket volumes, can also be provided to support service reviews and ongoing governance.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data through built-in reporting and administrative functions. Report-generated data can be exported directly by authorised users to Excel or CSV for operational and management purposes. For full contract exit or bulk data extraction, authorised supplier personnel perform structured data exports on behalf of the buyer to ensure security and data integrity. Export scope and timing are agreed in advance, and data is provided in commonly used formats such as Excel or CSV via secure transfer methods.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is designed for high availability and is delivered on resilient cloud infrastructure. The supplier guarantees 99.5% service availability, measured monthly, excluding planned maintenance and factors outside the supplier’s reasonable control.

Availability is monitored continuously, and performance is reviewed as part of regular service governance. If availability falls below the guaranteed level, service credits are applied in accordance with the agreed Service Level Agreement. Service credits are calculated as a percentage of the monthly service charge and are applied to future invoices.

Planned maintenance is scheduled outside core business hours wherever possible and is notified in advance. Full details of availability measurement, exclusions, and service credit application are provided within the contract documentation.
Approach to resilience
The service is designed with resilience as a core principle and is hosted on highly available cloud infrastructure. It operates across multiple, physically separate availability zones within the UK to protect against single points of failure. Infrastructure components are monitored continuously, with automated recovery mechanisms in place to maintain service continuity.

Data is stored on resilient, replicated storage with regular backups and tested recovery procedures. Application services are designed to tolerate component failure without service interruption where possible.

The underlying datacentre infrastructure is managed by AWS and includes resilient power, cooling, physical security, and environmental controls. Detailed architectural and resilience information can be provided to buyers on request, in line with security and assurance requirements.
Outage reporting
The service reports outages through clear, direct communication channels to ensure transparency and timely awareness.

There is no public status dashboard or outage reporting API. Service availability and incidents are monitored internally on a continuous basis.

In the event of a service outage or significant incident, email notifications are issued to nominated buyer contacts, providing details of the issue, current status, and expected resolution times where available. Updates are provided at appropriate intervals until service restoration is confirmed.

Outage information and incident summaries are also available through the service’s support ticketing system, allowing buyers to track progress and maintain an audit trail.

Post-incident reporting, including root cause analysis and corrective actions, can be provided on request as part of ongoing service governance and review processes.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through role-based access controls and secure authentication mechanisms. Only authorised users with appropriate permissions can access administrative functions, configuration settings, or sensitive data. Access is granted on a least-privilege basis and reviewed regularly.

Support channels are similarly restricted. Only nominated customer contacts can raise or manage support tickets, and identity verification is applied where support requests involve sensitive information or account changes. Supplier support staff access is controlled, logged, and limited to the minimum required to resolve issues. All access and administrative actions are audited to support accountability and security oversight.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is managed through a defined internal framework aligned with recognised best practices and government cloud security principles. The approach includes documented security policies, role-based access controls, and clear ownership of security responsibilities. Regular risk assessments, vulnerability management, and annual external penetration testing are carried out to identify and address risks. Security considerations are embedded into the software development lifecycle, with change management, access reviews, and incident response procedures in place to support ongoing compliance and service resilience.
Information security policies and processes
The organisation operates a set of documented information security policies and processes aligned with recognised best practice and government cloud security principles.

These policies cover areas including access control, data protection, secure software development, incident management, vulnerability management, backup and recovery, and supplier management. Policies are reviewed regularly and updated to reflect changes in risk, technology, or regulatory requirements.

Security responsibilities are clearly defined, with overall accountability held by senior management and day-to-day oversight managed by designated technical leads. Security incidents, risks, and compliance matters are reported through an internal escalation structure, ensuring visibility at management level.

Compliance with policies is supported through role-based access controls, mandatory use of secure development and operational practices, change management controls, and regular security reviews. External penetration testing and internal monitoring are used to validate that controls are operating effectively, and remediation actions are tracked to completion.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management are managed through defined internal processes aligned with operational security best practice. Service components are tracked through their lifecycle using version control, change records, and environment management controls. All changes are assessed for functional and security impact prior to implementation, including consideration of data protection, access controls, and service availability. Changes are tested in controlled environments before deployment, with rollback procedures in place. Security-related changes and incidents are reviewed and documented to support auditability and continuous improvement.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management is handled through defined internal processes aligned with operational security best practice. Potential threats are assessed using a combination of automated scanning, external penetration testing, and ongoing risk review. Vulnerabilities are prioritised based on severity, exploitability, and potential impact. Patches and mitigations are deployed promptly in line with risk, with critical issues addressed as a priority and tested before release. Information on emerging threats is obtained from cloud provider advisories, trusted security sources, vulnerability databases, and penetration testing reports.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is performed through continuous system and application monitoring, log collection, and automated alerts to identify potential compromises such as unusual access patterns, errors, or service anomalies. Logs are reviewed and retained to support investigation and audit requirements. When a potential compromise is identified, it is assessed promptly, escalated in line with incident response procedures, and appropriate containment and remediation actions are taken. Incidents are prioritised by severity, with critical incidents responded to immediately during support hours and managed through to resolution with documented outcomes.
Incident management type
Supplier-defined controls
Incident management approach
The organisation operates defined incident management processes to ensure timely and consistent response. Pre-defined procedures are in place for common events such as service outages, security incidents, and data protection issues. Users report incidents through email, phone, or the online ticketing system. Incidents are logged, prioritised, and managed in line with severity and impact. Updates are provided to users during incident resolution, and incident reports, including root cause and corrective actions, are supplied to buyers on request following resolution.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at maurice@thehirelab.com. Tell them what format you need. It will help if you say what assistive technology you use.