TruVPerm
A secure, cloud-based applicant tracking system supporting end-to-end recruitment from vacancy creation to appointment. It provides structured workflows, reporting, external/internal audit information with compliance functionality and candidate communication supported by a dedicated app. AI-assisted features support application review and shortlisting suggestions, operating as decision-support tools within configurable recruitment processes.
Features
- End-to-end vacancy and applicant management within a single platform
- Configurable recruitment workflows aligned to organisational hiring processes
- AI-assisted application summarisation and shortlisting decision support
- Secure candidate communications and automated status notifications
- Role-based access controls with comprehensive audit logging
- Reporting dashboards providing real-time recruitment pipeline visibility
- Integration with external HR, identity, and email systems
- Secure handling of personal, sensitive, and recruitment-related data
- Structured interview scheduling and outcome tracking within recruitment workflows
- Secure data export, retention management, and controlled service exit support
Benefits
- Reduced recruitment administration through structured, automated workflows
- Improved visibility across recruitment activity and candidate progress
- Faster shortlisting through AI-assisted application review
- Consistent recruitment processes across teams and departments
- Enhanced auditability and transparency of hiring decisions
- Secure handling of personal and sensitive recruitment data
- Improved candidate experience through timely, consistent communication
- Reduced risk through configurable controls and governance
- Easier collaboration between recruiters and hiring managers
- Scalable recruitment platform supporting organisational growth
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 5 0 8 1 6 8 9 0 6 6 9 6 2 0
Contact
EVISA SOLUTIONS LIMITED
Rob Shaw
Telephone: 07952 716878
Email: rob.shaw@malikshaw.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Robotic process automation
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
TruVPerm is provided as a cloud-based (SaaS) service and is not available for on-premise deployment. The service requires a modern web browser and internet connectivity for access. Recruitment workflows are configurable within the platform, but highly bespoke workflows may require additional design or change control. AI-assisted functionality provides decision-support only and does not automate recruitment decisions.
Integration with third-party systems is subject to availability of interfaces, permissions, and client-side readiness. Data residency is limited to supported cloud regions as agreed contractually. Service availability is subject to scheduled maintenance windows and the agreed service levels. - System requirements
-
- Modern, supported web browser (Chrome, Edge, Firefox, Safari)
- Reliable internet connection for web-based access
- Client-managed endpoint security in line with organisational policies
- HTTPS network access permitted through organisational firewalls
- Ability to receive system-generated email notifications
- Valid licences for any third-party systems integrated
- Client-managed user accounts and access permissions
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Support for the TruVPerm ATS is provided during UK business hours, with 24/7 coverage for critical incidents. Incidents are prioritised by severity, with critical issues receiving an initial response within one hour. High-priority issues are responded to within four hours, and medium-priority issues within one business day. Lower-priority service requests are acknowledged within two business days. Response times are measured from issue logging and supported by defined escalation and incident management processes.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- Web chat functionality is developed and tested using an accessibility-by-design approach aligned to WCAG 2.2 A. During development, web chat components are tested internally using common assistive technologies, including screen readers, keyboard-only navigation, and browser accessibility tools, to verify that core interactions such as opening chat, sending messages, receiving responses, and closing sessions are accessible. Testing focuses on ensuring logical focus order, clear labelling, readable message content, and compatibility with assistive technologies. Accessibility checks are incorporated into functional testing and release review. Where feedback is received from users requiring reasonable adjustments, this is reviewed and used to inform iterative improvements to the service.
- Onsite support
- Yes, at extra cost
- Support levels
- Support for TruVPerm is delivered through a structured, multi-channel service model designed to accommodate varying user needs and service priorities. Customers can raise and manage support requests via an online ticketing system, with clear prioritisation and visibility of progress. Web chat is available for general queries and guidance, while telephone support is provided for urgent or complex issues requiring real-time discussion. Where agreed, on-site support can be delivered for activities such as implementation, training, or issue resolution. All support channels operate within a coordinated framework to ensure consistent handling, appropriate escalation, and effective resolution in line with agreed service levels. Pricing is determined by organisational usage and selected service options and is agreed during the ordering process.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We support users in getting started with TruVPerm through a structured onboarding and enablement approach designed to suit different organisations and user needs. New customers are guided through an implementation and onboarding process that introduces the service, confirms configuration requirements, and supports initial setup. Users are provided with access to online training materials and user documentation that explain key features, workflows, and common tasks in clear, accessible language. Remote training sessions can be delivered to administrators and end users to support effective adoption. Where required and subject to agreement, onsite training can also be provided, particularly during initial implementation or for larger user groups. Ongoing support is available through the service support channels, including ticketing and web chat, to assist users as they begin using the service and as new users are onboarded.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- When the contract ends, users can extract their data through a controlled exit process. TruVPerm supports the secure export of customer data in commonly used, readable formats to enable transition to another system if required. Data exports are provided following customer instruction and in line with agreed data protection and information governance requirements. Once data has been successfully transferred and confirmed, remaining customer data is securely deleted or anonymised in accordance with contractual terms and UK data protection legislation.
- End-of-contract process
- At the end of the contract, standard data export and secure deletion in line with data protection requirements are included. Any additional costs would relate only to optional exit services requested by the customer, such as bespoke data extracts, extended data retention beyond agreed periods, additional support during transition to another system, or on-site assistance to support contract exit and handover.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No restricted ability
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The TruVPerm service interface is provided through a secure, browser-based web application accessible via modern web browsers, with no local software installation required. Users interact with the service through role-based dashboards that support vacancy management, application review, communications, reporting, and support access. The interface presents structured workflows, forms, and status views designed for clarity and ease of use. Support interfaces are integrated through online ticketing and web chat, with optional telephone support. Where configured, TruVPerm also provides system integrations via secure interfaces to exchange data with external HR, identity, and email systems.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- We tested the TruVPerm service interface using an accessibility-by-design approach aligned to WCAG 2.2.A. During development and release testing, key user journeys were validated with keyboard-only navigation and common assistive technologies, including screen readers and built-in browser accessibility tools, to confirm that core functions such as logging in, navigating workflows, completing forms, reviewing candidate information, and accessing support features are operable and understandable. Testing focused on logical reading and focus order, clear labelling, accessible error handling, and compatibility with assistive technologies. Findings were recorded and remediated as part of our quality assurance and change control process.
- API
- No
- Customisation available
- Yes
- Description of customisation
- The system allows users to tailor their experience based on their role and individual work priorities. Interface views, available functions, and task visibility can be configured so users see information that is most relevant to their responsibilities. This helps reduce unnecessary complexity, supports efficient working, and ensures that users can focus on the activities that matter most within their role.
Scaling
- Independence of resources
- TruVPerm is delivered as a managed, cloud-based service designed to support multiple customers without performance impact between users. The service operates within logically segregated environments with role-based access controls and data separation, ensuring that customer activity does not affect other users. The underlying infrastructure is monitored and scaled to meet demand, with service availability and performance managed as part of the SaaS service. Usage and performance are monitored to identify and address potential contention, ensuring a consistent and reliable experience for all users regardless of overall demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- TruVPerm provides service metrics that support operational oversight, performance monitoring, and governance. Users can access dashboards and reports showing recruitment activity, including vacancy status, candidate progression, workflow stages, and overall pipeline visibility. The service records user actions and system activity to provide audit logs and traceability. Service availability and incident information are monitored as part of the managed SaaS service. These metrics enable customers to track usage, identify bottlenecks, support compliance, and assess service performance over time.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data using built-in administrative export tools that allow authorised users to download datasets and reports in commonly used formats such as CSV or PDF. Where a full data extract is required, data is provided via a secure, managed transfer process (SFTP) following customer instruction and authorisation. We also support XML/JSON, API integration and database replication/syncing.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML/JSON
- SFTP
- API
- Database Replication/Syncing
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML/JSON
- SFTP
- API
- Database Replication/Syncing
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Data transferred between the buyer’s network and the TruVPerm service is protected using secure, encrypted communications. All access to the service is provided over HTTPS, ensuring data is encrypted in transit between user devices and the cloud-hosted service. Access is authenticated and controlled using role-based permissions, and no direct network connections into the buyer’s environment are required. These measures ensure that data remains protected from unauthorised access or interception while in transit between networks.
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- TruVPerm is provided as a managed, cloud-based service with a guaranteed availability target of 98.4% per calendar month, excluding agreed maintenance windows. The service is hosted on resilient AWS infrastructure designed to support high availability and scalability, with continuous monitoring to identify and address service-impacting issues. Availability is measured at the application level and aligned to defined service level agreements (SLAs) agreed with customers as part of the contract. Where TruVPerm fails to meet the guaranteed availability level, customers are entitled to service credits in accordance with the SLA. Service credits are calculated as a proportion of the affected subscription fees and are applied against future invoices rather than issued as cash refunds. This approach ensures transparency, accountability, and a clear mechanism for remediation where availability targets are not achieved.
- Approach to resilience
- Available on request
- Outage reporting
- Service outages are reported to clients directly via email. Notifications are issued promptly when an outage is identified and include information on the nature of the issue, expected impact, and progress updates. This approach is supported by monitored alerts from the underlying cloud infrastructure, enabling timely communication throughout an incident and ensuring customers are kept informed until service is fully restored.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through role-based access controls. Users are granted access only to the functions and data required for their role, with separate permissions for administrative, support, and standard user activities. Authentication is required for all access, and user actions are logged to provide activity reports. Third-party access is permitted where approved by the customer and controlled in the same way. Access can be reviewed and revoked as required to maintain security by the client.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Our security governance aligns with recognised standards, including Cyber Essentials and the NHS Data Security and Protection Toolkit. Our policies and processes are aligned with ISO best practices, including ISO/IEC 27001 for information security and ISO 9001 for quality management, supporting controlled and consistent service delivery.
- Information security policies and processes
-
Our information security policies and processes are aligned with the principles of ISO/IEC 27001 and focus on protecting the confidentiality, integrity, and availability of information. We maintain documented policies covering key areas including access control, data protection, risk management, incident response, supplier security, and business continuity. These policies define how information is handled, protected, and monitored across the organisation.
Information security governance is supported by a clear reporting structure, with senior management retaining overall accountability and designated security leads responsible for day-to-day implementation and oversight. Staff responsibilities are defined, and appropriate training is provided to ensure awareness of security obligations.
Compliance with policies is enforced through technical controls such as role-based access, secure system configuration, and audit logging, alongside procedural controls including documented processes and regular reviews. Security incidents or suspected non-compliance are reported through a formal incident management process, investigated, and addressed with corrective actions where required. Policies and controls are reviewed periodically to ensure they remain effective, proportionate, and aligned with evolving risks and business needs. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Service components are documented and tracked throughout their lifecycle, with configurations version controlled to maintain an accurate service baseline. Proposed changes follow a formal change process and are assessed for risk, including potential security impact, before approval. Security considerations such as data protection, access control, and availability are reviewed as part of each change. Approved changes are tested prior to implementation and deployed in a controlled manner, with records maintained to support traceability and ongoing governance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Potential threats are assessed using vulnerability scanning, penetration testing, and risk assessment to evaluate severity and impact. Security advisories, cloud provider notifications, and threat intelligence sources are used to identify emerging risks. Patches and mitigations are prioritised based on risk, with critical vulnerabilities addressed promptly and lower-risk issues scheduled through controlled change processes. All remediation actions are tested and tracked to ensure effective and timely resolution.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Potential compromises are detected through continuous monitoring, audit logging, and alerts from cloud infrastructure and application controls. When an issue is identified, it is assessed to determine impact and scope, and containment actions are initiated where required. Incidents are managed through a defined response process covering investigation, remediation, and reporting. Critical security incidents are responded to immediately, with assessment and escalation to ensure timely resolution and appropriate communication.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our incident management processes follow defined procedures designed to ensure timely and effective response to security and service incidents. Pre-defined processes are in place for common events, including service outages, security incidents, and data protection issues. Users can report incidents through the online support ticketing system, web chat, or by telephone for urgent issues. Incidents are logged, prioritised, and managed through a structured escalation and resolution process. Incident updates and outcomes are communicated to customers, with incident reports provided where appropriate, detailing impact, actions taken, and any preventative measures implemented.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-