Skip to main content

Help us improve the Digital Marketplace - send your feedback

EVISA SOLUTIONS LIMITED

TruVPerm

A secure, cloud-based applicant tracking system supporting end-to-end recruitment from vacancy creation to appointment. It provides structured workflows, reporting, external/internal audit information with compliance functionality and candidate communication supported by a dedicated app. AI-assisted features support application review and shortlisting suggestions, operating as decision-support tools within configurable recruitment processes.

Features

  • End-to-end vacancy and applicant management within a single platform
  • Configurable recruitment workflows aligned to organisational hiring processes
  • AI-assisted application summarisation and shortlisting decision support
  • Secure candidate communications and automated status notifications
  • Role-based access controls with comprehensive audit logging
  • Reporting dashboards providing real-time recruitment pipeline visibility
  • Integration with external HR, identity, and email systems
  • Secure handling of personal, sensitive, and recruitment-related data
  • Structured interview scheduling and outcome tracking within recruitment workflows
  • Secure data export, retention management, and controlled service exit support

Benefits

  • Reduced recruitment administration through structured, automated workflows
  • Improved visibility across recruitment activity and candidate progress
  • Faster shortlisting through AI-assisted application review
  • Consistent recruitment processes across teams and departments
  • Enhanced auditability and transparency of hiring decisions
  • Secure handling of personal and sensitive recruitment data
  • Improved candidate experience through timely, consistent communication
  • Reduced risk through configurable controls and governance
  • Easier collaboration between recruiters and hiring managers
  • Scalable recruitment platform supporting organisational growth

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at rob.shaw@malikshaw.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 5 0 8 1 6 8 9 0 6 6 9 6 2 0

Contact

EVISA SOLUTIONS LIMITED Rob Shaw
Telephone: 07952 716878
Email: rob.shaw@malikshaw.com

About your service

Service categories

Application Development and Deployment

Application platforms

  • Model driven application platforms
  • Robotic process automation
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
TruVPerm is provided as a cloud-based (SaaS) service and is not available for on-premise deployment. The service requires a modern web browser and internet connectivity for access. Recruitment workflows are configurable within the platform, but highly bespoke workflows may require additional design or change control. AI-assisted functionality provides decision-support only and does not automate recruitment decisions.
Integration with third-party systems is subject to availability of interfaces, permissions, and client-side readiness. Data residency is limited to supported cloud regions as agreed contractually. Service availability is subject to scheduled maintenance windows and the agreed service levels.
System requirements
  • Modern, supported web browser (Chrome, Edge, Firefox, Safari)
  • Reliable internet connection for web-based access
  • Client-managed endpoint security in line with organisational policies
  • HTTPS network access permitted through organisational firewalls
  • Ability to receive system-generated email notifications
  • Valid licences for any third-party systems integrated
  • Client-managed user accounts and access permissions

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Support for the TruVPerm ATS is provided during UK business hours, with 24/7 coverage for critical incidents. Incidents are prioritised by severity, with critical issues receiving an initial response within one hour. High-priority issues are responded to within four hours, and medium-priority issues within one business day. Lower-priority service requests are acknowledged within two business days. Response times are measured from issue logging and supported by defined escalation and incident management processes.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 A
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes, at an extra cost
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 A
Web chat accessibility testing
Web chat functionality is developed and tested using an accessibility-by-design approach aligned to WCAG 2.2 A. During development, web chat components are tested internally using common assistive technologies, including screen readers, keyboard-only navigation, and browser accessibility tools, to verify that core interactions such as opening chat, sending messages, receiving responses, and closing sessions are accessible. Testing focuses on ensuring logical focus order, clear labelling, readable message content, and compatibility with assistive technologies. Accessibility checks are incorporated into functional testing and release review. Where feedback is received from users requiring reasonable adjustments, this is reviewed and used to inform iterative improvements to the service.
Onsite support
Yes, at extra cost
Support levels
Support for TruVPerm is delivered through a structured, multi-channel service model designed to accommodate varying user needs and service priorities. Customers can raise and manage support requests via an online ticketing system, with clear prioritisation and visibility of progress. Web chat is available for general queries and guidance, while telephone support is provided for urgent or complex issues requiring real-time discussion. Where agreed, on-site support can be delivered for activities such as implementation, training, or issue resolution. All support channels operate within a coordinated framework to ensure consistent handling, appropriate escalation, and effective resolution in line with agreed service levels. Pricing is determined by organisational usage and selected service options and is agreed during the ordering process.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We support users in getting started with TruVPerm through a structured onboarding and enablement approach designed to suit different organisations and user needs. New customers are guided through an implementation and onboarding process that introduces the service, confirms configuration requirements, and supports initial setup. Users are provided with access to online training materials and user documentation that explain key features, workflows, and common tasks in clear, accessible language. Remote training sessions can be delivered to administrators and end users to support effective adoption. Where required and subject to agreement, onsite training can also be provided, particularly during initial implementation or for larger user groups. Ongoing support is available through the service support channels, including ticketing and web chat, to assist users as they begin using the service and as new users are onboarded.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When the contract ends, users can extract their data through a controlled exit process. TruVPerm supports the secure export of customer data in commonly used, readable formats to enable transition to another system if required. Data exports are provided following customer instruction and in line with agreed data protection and information governance requirements. Once data has been successfully transferred and confirmed, remaining customer data is securely deleted or anonymised in accordance with contractual terms and UK data protection legislation.
End-of-contract process
At the end of the contract, standard data export and secure deletion in line with data protection requirements are included. Any additional costs would relate only to optional exit services requested by the customer, such as bespoke data extracts, extended data retention beyond agreed periods, additional support during transition to another system, or on-site assistance to support contract exit and handover.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
No restricted ability
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
The TruVPerm service interface is provided through a secure, browser-based web application accessible via modern web browsers, with no local software installation required. Users interact with the service through role-based dashboards that support vacancy management, application review, communications, reporting, and support access. The interface presents structured workflows, forms, and status views designed for clarity and ease of use. Support interfaces are integrated through online ticketing and web chat, with optional telephone support. Where configured, TruVPerm also provides system integrations via secure interfaces to exchange data with external HR, identity, and email systems.
Accessibility standards
WCAG 2.2 A
Accessibility testing
We tested the TruVPerm service interface using an accessibility-by-design approach aligned to WCAG 2.2.A. During development and release testing, key user journeys were validated with keyboard-only navigation and common assistive technologies, including screen readers and built-in browser accessibility tools, to confirm that core functions such as logging in, navigating workflows, completing forms, reviewing candidate information, and accessing support features are operable and understandable. Testing focused on logical reading and focus order, clear labelling, accessible error handling, and compatibility with assistive technologies. Findings were recorded and remediated as part of our quality assurance and change control process.
API
No
Customisation available
Yes
Description of customisation
The system allows users to tailor their experience based on their role and individual work priorities. Interface views, available functions, and task visibility can be configured so users see information that is most relevant to their responsibilities. This helps reduce unnecessary complexity, supports efficient working, and ensures that users can focus on the activities that matter most within their role.

Scaling

Independence of resources
TruVPerm is delivered as a managed, cloud-based service designed to support multiple customers without performance impact between users. The service operates within logically segregated environments with role-based access controls and data separation, ensuring that customer activity does not affect other users. The underlying infrastructure is monitored and scaled to meet demand, with service availability and performance managed as part of the SaaS service. Usage and performance are monitored to identify and address potential contention, ensuring a consistent and reliable experience for all users regardless of overall demand.

Analytics

Service usage metrics
Yes
Metrics types
TruVPerm provides service metrics that support operational oversight, performance monitoring, and governance. Users can access dashboards and reports showing recruitment activity, including vacancy status, candidate progression, workflow stages, and overall pipeline visibility. The service records user actions and system activity to provide audit logs and traceability. Service availability and incident information are monitored as part of the managed SaaS service. These metrics enable customers to track usage, identify bottlenecks, support compliance, and assess service performance over time.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users can export their data using built-in administrative export tools that allow authorised users to download datasets and reports in commonly used formats such as CSV or PDF. Where a full data extract is required, data is provided via a secure, managed transfer process (SFTP) following customer instruction and authorisation. We also support XML/JSON, API integration and database replication/syncing.
Data export formats
  • CSV
  • Other
Other data export formats
  • XML/JSON
  • SFTP
  • API
  • Database Replication/Syncing
Data import formats
  • CSV
  • Other
Other data import formats
  • XML/JSON
  • SFTP
  • API
  • Database Replication/Syncing

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
Data transferred between the buyer’s network and the TruVPerm service is protected using secure, encrypted communications. All access to the service is provided over HTTPS, ensuring data is encrypted in transit between user devices and the cloud-hosted service. Access is authenticated and controlled using role-based permissions, and no direct network connections into the buyer’s environment are required. These measures ensure that data remains protected from unauthorised access or interception while in transit between networks.
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
TruVPerm is provided as a managed, cloud-based service with a guaranteed availability target of 98.4% per calendar month, excluding agreed maintenance windows. The service is hosted on resilient AWS infrastructure designed to support high availability and scalability, with continuous monitoring to identify and address service-impacting issues. Availability is measured at the application level and aligned to defined service level agreements (SLAs) agreed with customers as part of the contract. Where TruVPerm fails to meet the guaranteed availability level, customers are entitled to service credits in accordance with the SLA. Service credits are calculated as a proportion of the affected subscription fees and are applied against future invoices rather than issued as cash refunds. This approach ensures transparency, accountability, and a clear mechanism for remediation where availability targets are not achieved.
Approach to resilience
Available on request
Outage reporting
Service outages are reported to clients directly via email. Notifications are issued promptly when an outage is identified and include information on the nature of the issue, expected impact, and progress updates. This approach is supported by monitored alerts from the underlying cloud infrastructure, enabling timely communication throughout an incident and ensuring customers are kept informed until service is fully restored.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through role-based access controls. Users are granted access only to the functions and data required for their role, with separate permissions for administrative, support, and standard user activities. Authentication is required for all access, and user actions are logged to provide activity reports. Third-party access is permitted where approved by the customer and controlled in the same way. Access can be reviewed and revoked as required to maintain security by the client.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Our security governance aligns with recognised standards, including Cyber Essentials and the NHS Data Security and Protection Toolkit. Our policies and processes are aligned with ISO best practices, including ISO/IEC 27001 for information security and ISO 9001 for quality management, supporting controlled and consistent service delivery.
Information security policies and processes
Our information security policies and processes are aligned with the principles of ISO/IEC 27001 and focus on protecting the confidentiality, integrity, and availability of information. We maintain documented policies covering key areas including access control, data protection, risk management, incident response, supplier security, and business continuity. These policies define how information is handled, protected, and monitored across the organisation.
Information security governance is supported by a clear reporting structure, with senior management retaining overall accountability and designated security leads responsible for day-to-day implementation and oversight. Staff responsibilities are defined, and appropriate training is provided to ensure awareness of security obligations.
Compliance with policies is enforced through technical controls such as role-based access, secure system configuration, and audit logging, alongside procedural controls including documented processes and regular reviews. Security incidents or suspected non-compliance are reported through a formal incident management process, investigated, and addressed with corrective actions where required. Policies and controls are reviewed periodically to ensure they remain effective, proportionate, and aligned with evolving risks and business needs.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Service components are documented and tracked throughout their lifecycle, with configurations version controlled to maintain an accurate service baseline. Proposed changes follow a formal change process and are assessed for risk, including potential security impact, before approval. Security considerations such as data protection, access control, and availability are reviewed as part of each change. Approved changes are tested prior to implementation and deployed in a controlled manner, with records maintained to support traceability and ongoing governance.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Potential threats are assessed using vulnerability scanning, penetration testing, and risk assessment to evaluate severity and impact. Security advisories, cloud provider notifications, and threat intelligence sources are used to identify emerging risks. Patches and mitigations are prioritised based on risk, with critical vulnerabilities addressed promptly and lower-risk issues scheduled through controlled change processes. All remediation actions are tested and tracked to ensure effective and timely resolution.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Potential compromises are detected through continuous monitoring, audit logging, and alerts from cloud infrastructure and application controls. When an issue is identified, it is assessed to determine impact and scope, and containment actions are initiated where required. Incidents are managed through a defined response process covering investigation, remediation, and reporting. Critical security incidents are responded to immediately, with assessment and escalation to ensure timely resolution and appropriate communication.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our incident management processes follow defined procedures designed to ensure timely and effective response to security and service incidents. Pre-defined processes are in place for common events, including service outages, security incidents, and data protection issues. Users can report incidents through the online support ticketing system, web chat, or by telephone for urgent issues. Incidents are logged, prioritised, and managed through a structured escalation and resolution process. Incident updates and outcomes are communicated to customers, with incident reports provided where appropriate, detailing impact, actions taken, and any preventative measures implemented.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at rob.shaw@malikshaw.com. Tell them what format you need. It will help if you say what assistive technology you use.