Skip to main content

Help us improve the Digital Marketplace - send your feedback

HACKAJOB LTD

Source

Source enables employers to search and shortlist candidates from hackajob’s private community, then send interview requests. AI-assisted prompts, job description parsing and explainable profile insights improve match quality and reduce time spent on manual sourcing.

Features

  • AI search prompt from free text, or JD upload
  • Job description parsing to extract requirements and criteria
  • Auto-generated skills and background filters from the prompt
  • Editable filters with tooltips explaining interpretation of requirements
  • Candidate search and matching across hackajob private community
  • AI profile summaries aligned to role criteria
  • Evidence highlighting for skills and experience on profiles
  • Knowledge-graph matching to relate skills and equivalent experience
  • Shortlist management and interview requests from within the platform
  • ATS integrations to support candidate workflow and status updates

Benefits

  • Find relevant candidates faster with AI-powered search
  • Reduce manual sourcing time with simplified queries and filters
  • Focus on high-fit profiles
  • Make faster decisions with clear, explainable candidate insights
  • Improve fairness by matching on skills, experience, preferences
  • Create shortlists quickly and manage pipelines in one place
  • Reduce time-to-interview by streamlining outreach and requests
  • Align stakeholders with consistent, structured evaluation criteria
  • Improve candidate experience with timely engagement and follow-up

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mark@hackajob.co. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 3 7 0 3 7 5 5 2 1 1 5 9 8 9

Contact

HACKAJOB LTD Mark Chaffey
Telephone: 07775863524
Email: mark@hackajob.co

About your service

Service categories

Applications

Enterprise resource management

Human capital management

  • Talent Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
N/A
System requirements
  • Modern web browser (Chrome, Safari, Firefox).
  • Stable internet connection.
  • Email access to receive invitations and notifications.

User support

Email or online ticketing support
Yes
Support response times
Support is provided via email/ticketing during UK business hours (09:00–17:00, Monday–Friday, GMT/BST). Weekend and public holiday support is not included; urgent issues raised out of hours are responded to next business day.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
No
Support levels
Support is included in the subscription price. We provide two support levels: (1) Customer Success support via an allocated Customer Success Manager for onboarding, product guidance, configuration support and best practice; and (2) Technical Support for incidents, defects and technical queries, handled by our Product/Engineering support team as required.
Support available to third parties
No

Onboarding and offboarding

Getting started
An allocated Customer Success Manager supports onboarding and go-live. For implementation and enablement, we can also provide a Forward Deployed Engineer (FDE) who acts as a dedicated product specialist to help configure roles/jobs, support integrations (for example ATS), and deliver hands-on training for administrators and end users. Training is typically delivered remotely (video call) with role-based walkthroughs and Q&A. Users also have access to online guidance (how-to articles and release notes). Ongoing support is available via email/ticketing during UK business hours, with refresher sessions available on request.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
On contract end, the customer can request a copy of their Client Content. We will provide a copy of the most recent back-up within 30 days of the customer’s request (at the customer’s cost), via a secure transfer method agreed with the customer. We retain Client Content in backup media for up to one year after termination (or longer if required by law) and make no further use of it.
End-of-contract process
At the end of the contract, access to the service is removed in line with the agreed termination/expiry date and the customer’s users are deactivated. We will support an orderly offboarding via the allocated Customer Success Manager / Forward Deployed Engineer, including confirming the end date, final service actions, and (if required) agreeing a secure method for returning customer data.
What’s included in the contract price: standard offboarding support and guidance during UK business hours (Mon–Fri).
Data handling: customer data is retained and deleted in line with our contractual retention and backup practices and any legal obligations.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided online via our knowledge base (HTML) and can be shared as PDF on request. Documentation is accessible via a standard web browser and can be provided in alternative formats where required. An allocated Customer Success Manager / Forward Deployed Engineer can also walk users through onboarding/offboarding steps in live remote sessions and provide follow-up written guidance.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
No

Scaling

Independence of resources
We minimise the impact of other users’ demand through scalable AWS infrastructure, tenant isolation and capacity management. The service uses monitored, load-balanced components with auto-scaling and resource limits to prevent noisy-neighbour effects. Performance and availability are tracked using real-time monitoring and are managed under our ISO 27001 risk and incident management processes.

Analytics

Service usage metrics
Yes
Metrics types
We provide service usage and outcome metrics via in-product reporting and regular service reviews, including: weekly active users; profile views; qualified candidates identified; profile-view-to-progression ratio; progression rate (interview requests / total decisions); successful match rate (candidates progressing to stage 1); interview request and acceptance rate; and review outcomes (dismiss/progress reasons). Metrics can be segmented by role, team and time period.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Customer data is encrypted at rest using AWS managed encryption (AES-256) for databases, storage and backups. Encryption key management follows AWS best practices and access controls. Access to production data is restricted using least privilege and logging/monitoring. Data is hosted in AWS (Ireland region).
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can request an export via their Customer Success Manager or support. We confirm the scope and provide the export within an agreed timeframe (typically within 30 days for end-of-contract requests). Data is provided via a secure transfer method agreed with the customer (for example encrypted file transfer). Exports are handled in line with our contractual terms and applicable data protection requirements.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
Other
Other data import formats
N/A

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We provide a 99% availability SLA: the system is made available to users 24/7, with a KPI of 99%. Support is provided Monday–Friday, 09:00–17:00 GMT (restricted service on public holidays). Incident response/target resolution: Severity 1 (unplanned outage impacting multiple users) 1 hour response, <24 hours target resolution; Severity 2 (outage/severe disruption for several users) 2 hours response, within 2 working days; Severity 3 (reduced functionality causing disruption) 4 hours response, within 3 working days; Severity 4 (non-urgent/low impact) 8 hours response, within 5 working days. The terms state we use reasonable endeavours and response times are for acknowledgement. No automatic service credits/refunds are specified; remedies are handled in line with the contract.
Approach to resilience
The service is hosted on AWS (Ireland region) and is designed for resilience using redundant, load-balanced components and automated scaling. We use monitored infrastructure, alerting and incident management to maintain availability, with planned maintenance managed and communicated. Data is backed up and can be restored in line with our disaster recovery processes. Security and operational resilience are managed under our ISO 27001-certified ISMS and SOC 2 controls. Data is encrypted in transit (TLS) and at rest (AES-256).
Outage reporting
We report service incidents and outages via our public status page, where users can subscribe to updates (email). For major incidents we also notify affected customers directly via email through their support contacts, and provide progress updates until resolution and a post-incident summary where appropriate.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
IdP-Initiated SAML 2.0 SSO
Access restrictions in management interfaces and support channels
Access to management/admin interfaces is restricted to authorised hackajob staff on a least-privilege basis, using role-based access controls, MFA and audit logging. Administrative access is limited to approved accounts and can be further restricted via VPN and IP controls where required. Support requests are handled via authenticated customer contacts (named CSM contacts) and ticketing/email; identity is verified before making account changes or sharing data. Privileged access is reviewed regularly and removed promptly when no longer required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
Single Sign-On, VPN with whitelisted IP

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We operate an ISO/IEC 27001:2022-certified Information Security Management System (ISMS). This includes documented policies and procedures covering risk assessment and treatment, access control, secure development/change management, supplier security, incident management, business continuity, and data protection. Risks are owned by control/process owners, reviewed through the ISMS risk register, and escalated to senior management where approval is required. Compliance is supported through onboarding and annual security training, role-based access controls, logging/monitoring, internal audits, management reviews, and corrective actions to address any non-conformities. Policy enforcement is achieved through management sign-offs, internal audits, training, regular reviews, and external certifications.

Policy enforcement is achieved through management sign-offs, internal audits, training, regular reviews, and external certifications.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Changes to software, infrastructure and configuration follow a formal change process. All changes are tracked in version control/ticketing, security impact is assessed, peer reviewed and approved before release. Changes are tested in non-production environments and deployed via controlled release procedures with audit logs. Assets are inventoried in a Hardware Asset Register and their lifecycles tracked. Changes are assessed via the ISO 27001 risk process, with high/medium risks requiring treatment approval by management.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management process aligns with ISO/IEC 27001 and our ISMS risk assessment policy.

Assessing potential threats: We maintain an asset inventory (Hardware Asset Register), identify threats (e.g., malware, fire) per asset, and assess vulnerabilities (e.g., unpatched servers) via group discussions and stakeholder interviews.

Patch deployment: Integrated into IT change management and project risk assessments; patches deployed promptly post-evaluation to mitigate high/medium risks, prioritizing based on likelihood (1-5 scale) x impact (1-5) scores.

Threat sources: Internal reviews, external changes (legislation, breaches), standards (ISO 27002/17/18), and supplier evaluations.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We use AWS Tools (Inspector, GuardDuty, Detective), GitHub Dependabot, Coralogix & Datadog for monitoring of logs, privileged access, failures and anomalies.

Real time threat detection via GuardDuty/Detective, vulnerability scans via Inspector/Dependabot, and SIEM alerts identify unauthorised access or exploits.

As soon as we're made aware of any compromise/incident our Incident Response Plan activates to contain, eradicate and recover the threat, or escalate via our Business Continuity & Disaster Recovery Policy.

Our response times for multi-user outage are under 1 hour acknowledgement and 24 hours resolve.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Hackajob's Incident Management Policy (within ISMS) defines processes for detection, reporting, assessment, prioritization (High/Medium/Low via impact on assets/business), response, and recovery—via Flowchart and Procedure. Users report incidents immediately to IT Service Desk/CTO per procedure. Reports use Notion's Incident Tracking Document (timeline, actions, impact) linked in a dedicated Slack channel. Internal comms via Slack; external (customers, regulators, media) by IMT with pre-written statements, legal review, and logs for compliance.
Customers can report incidents via support email/ticketing. We provide incident updates and a post-incident report (including root cause and corrective actions) for material incidents
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Hackajob can provide a trial of the service, without limitations, up to 30-days or until a hire is made.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Accorp Partners Cert Inc.
ISO/IEC 27001 accreditation date
Thursday 24 April 2025
What the ISO/IEC 27001 doesn’t cover
Hackajob’s ISO/IEC 27001 certification covers the Information Security Management System (ISMS) scope defined for hackajob Ltd, including the infrastructure, applications and systems used to deliver our services, and the activities and business functions that hold, obtain, share or manage customer and business data.
Items not covered are those outside this ISMS scope, including:

Customer-controlled environments and configurations (for example, the customer’s ATS, user devices/endpoints, networks, and identity provider/SSO configuration).

Third-party systems or services not operated or controlled by hackajob, except to the extent they are managed through our supplier risk management process.

Data, systems, or processes that sit outside hackajob Ltd’s audited scope (for example, customer internal processes, and any customer-side storage, exports, or onward sharing performed by the customer).

Security controls and processes that are the customer’s responsibility under the shared responsibility model (for example, user access administration and joiners/movers/leavers decisions).
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
SOC 2 Type 1

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mark@hackajob.co. Tell them what format you need. It will help if you say what assistive technology you use.