Refapp
Refapp is a talent intelligence solution that helps recruiters conduct efficient, professional, and secure reference checks on each candidate. Using a fully automated and science-based workflow, you benefit from reliable and relevant information, the candidate from a fair process, and the reference from a smooth experience.
Features
- Fully digital and automated workflow
- Phone call booking feature
- Brand your communications
- Fraud detection
- Lead generation feature
- Professional reporting
Benefits
- Make Better Recruitment Decisions
- Structured and standardised reference checking removes cognitive bias
- Save time in your recruitment process with automated workflow
- Employer Branding: Professional and smooth communication with referees and customers
- Non-discriminatory: Refapp removes the risk of discriminatory questions
- GDPR Compliant: information is stored encrypted with the highest security
Pricing
£200 to £4,000 an instance a month
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
2 2 3 3 8 5 7 2 0 7 7 3 2 5 1
Contact
Talentwise AB
David Näsström
Telephone: +46733573627
Email: david.nasstrom@refapp.com
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Most ATSs. See https://www.refapp.com/integrations
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Service constraints
- No
- System requirements
-
- Internet access
- Web browser
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
We offer support services through second-line support
between 08:00 - 16:30 (CET). More info in our SLA. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Onsite support
- Support levels
-
Level 1. Critical shutdown for all users. The system is inaccessible and there is a severe impact in processes. Within four (4) hours after registered notification during Office hours.
Level 2. High System is inaccessible to single users or a
process-critical function is unavailable. At the latest during the following
working day after registered notification.
Level 3. Low Function does not correspond to expected behavior but
does not affect the process to major extent. Within two releases at the latest. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
- Pre recorded online training sessions.
- Dedicated Customer Success Manager have training sessions. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Copies of data can be provided upon contract end. The extracted data for the client can be provided as a database export.
- End-of-contract process
- System access is revoked on the contract end date unless otherwise agreed. In line with the contract, at the written direction of the Controller, unless a copy is specifically required to be retained by the Processor for audit or compliance purposes in performance of its obligations for up to two (2) years, the Processor will delete or return Personal Data (and any copies of it) to the Controller on termination of the Contract unless the Processor is required by Law to retain the Personal Data.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No differences.
- Service interface
- No
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- API
- Yes
- What users can and can't do using the API
- Integrate our plattform to ATS/CRM/HRIS
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
- Questionnaire
- branding (logo and accent color)
- communication
Scaling
- Independence of resources
- We constantly monitor individual customer instance system usage levels, this enables us to increase resources proactively for customers with growing usage profile. Webservers are load balanced using a failover methodology to ensure high availability. All load balancers and firewalls also have redundancy built in.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Admin user have access to the "company statistics" site with the following data:
# New Candidates
# New Referees
Reply Rate
Contacted via email
Contacted via SMS
Average time to reply
Typical time to reply
# New Leads
Likes Refapp 👍
Verified reference
Active Users
Time to answer
Completed Reports
Average word count - Reporting types
- Real-time dashboards
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with SSAE-16 / ISAE 3402
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Data can be exported from the system in CSV or PDF format. Use of the system includes access to a bespoke report builder and a set of standard reports which cover key metrics, the data output can be saved locally in a CSV of PDF format. Four bulk upload functions exist on the system, each requires the completion of a template CSV file which allows for applications, users and Business Units to be uploaded in bulk to the system.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Json
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We target an SLA for overall system availability of 99.5% minimum over 24/7/365. We regularly exceed this and most customers have an uptime of 100% each month. If we fail to meet 99.5% in a given month, the period of downtime is added on free of charge at the end of the contract.
- Approach to resilience
- This information is available on request.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Limited access network (for example PSN)
- Username or password
- Other
- Other user authentication
- Single Sign-On is also available
- Access restrictions in management interfaces and support channels
- Access to system data is controlled and only authorised personnel have access. The database itself is password protected. Refapp is hosted upon dedicated servers which are utilised for no other purpose than for the Refapp system. The Refapp system records and time, date and user stamps the access to all records within the system and therefore offers a clear audit trail to correlate with any security events.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Username or password
- Other
- Description of management access authentication
- Single Sign-On is also available
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- This information is available on request.
- Information security policies and processes
-
The Information Security Management System of Refapp (Talentwise AB) consists of the following sections and artefacts:
- Analysis
- Policies
- Procedures
- Records
More information is given upon request.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Details related to our configuration and change management policies and procedures can be provided to clients upon request.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Details related to our vulnerability management policies and procedures can be provided to clients upon request.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Details related to our software security, monitoring, and our incident response policies and procedures can be provided to clients upon request.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Details related to our security incident management policies and procedures can be provided to clients upon request.
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Equal opportunity
Fighting climate change
Talentwise strives to have as little negative impact possible on our environment. We do this through our own choice of service and products we purchase, by employees doing active choices and when given the opportunity to influence our customers. The company's CEO is ultimately responsible for ensuring that our environmental policy is met.
We ensure our customers that all our employees always take the environmental impact into account when making purchases, doing system development and travel. When possible one should choose alternatives with the least negative or preferably the most positive environmental impact, examples;
- Traveling by train instead of plane
- To offer employees to work from home to reduce commuting
- To build functions in systems we deliver to reduce our customers' environmental impact
- Not to buy products or services without analyzing the producers' declaration of environmental impact
We also promise to constantly improve in this field by:
- Train employees in environmental issues on a regular basis
- When given the opportunity engage the company in environmental collaborations with suppliers and customers
In order to comply with this environmental policy and constantly improve, we establish and follow up environmental goals according to our environmental policy.Covid-19 recovery
During Covid-19 , march 2020, aprox 20 hospitals in Sweden used Refapp to conduct referencing on voluntary workers. Refapp did this pro bono.Equal opportunity
Refapp removes the risk of discriminatory questions by allowing a standardised question set for every candidate.
Pricing
- Price
- £200 to £4,000 an instance a month
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- 14 days free trial.
- Link to free trial
- https://www.refapp.com/signup-free-trial