Source
Source enables employers to search and shortlist candidates from hackajob’s private community, then send interview requests. AI-assisted prompts, job description parsing and explainable profile insights improve match quality and reduce time spent on manual sourcing.
Features
- AI search prompt from free text, or JD upload
- Job description parsing to extract requirements and criteria
- Auto-generated skills and background filters from the prompt
- Editable filters with tooltips explaining interpretation of requirements
- Candidate search and matching across hackajob private community
- AI profile summaries aligned to role criteria
- Evidence highlighting for skills and experience on profiles
- Knowledge-graph matching to relate skills and equivalent experience
- Shortlist management and interview requests from within the platform
- ATS integrations to support candidate workflow and status updates
Benefits
- Find relevant candidates faster with AI-powered search
- Reduce manual sourcing time with simplified queries and filters
- Focus on high-fit profiles
- Make faster decisions with clear, explainable candidate insights
- Improve fairness by matching on skills, experience, preferences
- Create shortlists quickly and manage pipelines in one place
- Reduce time-to-interview by streamlining outreach and requests
- Align stakeholders with consistent, structured evaluation criteria
- Improve candidate experience with timely engagement and follow-up
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 3 7 0 3 7 5 5 2 1 1 5 9 8 9
Contact
HACKAJOB LTD
Mark Chaffey
Telephone: 07775863524
Email: mark@hackajob.co
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- N/A
- System requirements
-
- Modern web browser (Chrome, Safari, Firefox).
- Stable internet connection.
- Email access to receive invitations and notifications.
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is provided via email/ticketing during UK business hours (09:00–17:00, Monday–Friday, GMT/BST). Weekend and public holiday support is not included; urgent issues raised out of hours are responded to next business day.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- Support is included in the subscription price. We provide two support levels: (1) Customer Success support via an allocated Customer Success Manager for onboarding, product guidance, configuration support and best practice; and (2) Technical Support for incidents, defects and technical queries, handled by our Product/Engineering support team as required.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- An allocated Customer Success Manager supports onboarding and go-live. For implementation and enablement, we can also provide a Forward Deployed Engineer (FDE) who acts as a dedicated product specialist to help configure roles/jobs, support integrations (for example ATS), and deliver hands-on training for administrators and end users. Training is typically delivered remotely (video call) with role-based walkthroughs and Q&A. Users also have access to online guidance (how-to articles and release notes). Ongoing support is available via email/ticketing during UK business hours, with refresher sessions available on request.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- On contract end, the customer can request a copy of their Client Content. We will provide a copy of the most recent back-up within 30 days of the customer’s request (at the customer’s cost), via a secure transfer method agreed with the customer. We retain Client Content in backup media for up to one year after termination (or longer if required by law) and make no further use of it.
- End-of-contract process
-
At the end of the contract, access to the service is removed in line with the agreed termination/expiry date and the customer’s users are deactivated. We will support an orderly offboarding via the allocated Customer Success Manager / Forward Deployed Engineer, including confirming the end date, final service actions, and (if required) agreeing a secure method for returning customer data.
What’s included in the contract price: standard offboarding support and guidance during UK business hours (Mon–Fri).
Data handling: customer data is retained and deleted in line with our contractual retention and backup practices and any legal obligations. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation is provided online via our knowledge base (HTML) and can be shared as PDF on request. Documentation is accessible via a standard web browser and can be provided in alternative formats where required. An allocated Customer Success Manager / Forward Deployed Engineer can also walk users through onboarding/offboarding steps in live remote sessions and provide follow-up written guidance.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- We minimise the impact of other users’ demand through scalable AWS infrastructure, tenant isolation and capacity management. The service uses monitored, load-balanced components with auto-scaling and resource limits to prevent noisy-neighbour effects. Performance and availability are tracked using real-time monitoring and are managed under our ISO 27001 risk and incident management processes.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service usage and outcome metrics via in-product reporting and regular service reviews, including: weekly active users; profile views; qualified candidates identified; profile-view-to-progression ratio; progression rate (interview requests / total decisions); successful match rate (candidates progressing to stage 1); interview request and acceptance rate; and review outcomes (dismiss/progress reasons). Metrics can be segmented by role, team and time period.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Customer data is encrypted at rest using AWS managed encryption (AES-256) for databases, storage and backups. Encryption key management follows AWS best practices and access controls. Access to production data is restricted using least privilege and logging/monitoring. Data is hosted in AWS (Ireland region).
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can request an export via their Customer Success Manager or support. We confirm the scope and provide the export within an agreed timeframe (typically within 30 days for end-of-contract requests). Data is provided via a secure transfer method agreed with the customer (for example encrypted file transfer). Exports are handled in line with our contractual terms and applicable data protection requirements.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
- Other
- Other data import formats
- N/A
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We provide a 99% availability SLA: the system is made available to users 24/7, with a KPI of 99%. Support is provided Monday–Friday, 09:00–17:00 GMT (restricted service on public holidays). Incident response/target resolution: Severity 1 (unplanned outage impacting multiple users) 1 hour response, <24 hours target resolution; Severity 2 (outage/severe disruption for several users) 2 hours response, within 2 working days; Severity 3 (reduced functionality causing disruption) 4 hours response, within 3 working days; Severity 4 (non-urgent/low impact) 8 hours response, within 5 working days. The terms state we use reasonable endeavours and response times are for acknowledgement. No automatic service credits/refunds are specified; remedies are handled in line with the contract.
- Approach to resilience
- The service is hosted on AWS (Ireland region) and is designed for resilience using redundant, load-balanced components and automated scaling. We use monitored infrastructure, alerting and incident management to maintain availability, with planned maintenance managed and communicated. Data is backed up and can be restored in line with our disaster recovery processes. Security and operational resilience are managed under our ISO 27001-certified ISMS and SOC 2 controls. Data is encrypted in transit (TLS) and at rest (AES-256).
- Outage reporting
- We report service incidents and outages via our public status page, where users can subscribe to updates (email). For major incidents we also notify affected customers directly via email through their support contacts, and provide progress updates until resolution and a post-incident summary where appropriate.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- IdP-Initiated SAML 2.0 SSO
- Access restrictions in management interfaces and support channels
- Access to management/admin interfaces is restricted to authorised hackajob staff on a least-privilege basis, using role-based access controls, MFA and audit logging. Administrative access is limited to approved accounts and can be further restricted via VPN and IP controls where required. Support requests are handled via authenticated customer contacts (named CSM contacts) and ticketing/email; identity is verified before making account changes or sharing data. Privileged access is reviewed regularly and removed promptly when no longer required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Single Sign-On, VPN with whitelisted IP
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate an ISO/IEC 27001:2022-certified Information Security Management System (ISMS). This includes documented policies and procedures covering risk assessment and treatment, access control, secure development/change management, supplier security, incident management, business continuity, and data protection. Risks are owned by control/process owners, reviewed through the ISMS risk register, and escalated to senior management where approval is required. Compliance is supported through onboarding and annual security training, role-based access controls, logging/monitoring, internal audits, management reviews, and corrective actions to address any non-conformities. Policy enforcement is achieved through management sign-offs, internal audits, training, regular reviews, and external certifications.
Policy enforcement is achieved through management sign-offs, internal audits, training, regular reviews, and external certifications. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Changes to software, infrastructure and configuration follow a formal change process. All changes are tracked in version control/ticketing, security impact is assessed, peer reviewed and approved before release. Changes are tested in non-production environments and deployed via controlled release procedures with audit logs. Assets are inventoried in a Hardware Asset Register and their lifecycles tracked. Changes are assessed via the ISO 27001 risk process, with high/medium risks requiring treatment approval by management.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Our vulnerability management process aligns with ISO/IEC 27001 and our ISMS risk assessment policy.
Assessing potential threats: We maintain an asset inventory (Hardware Asset Register), identify threats (e.g., malware, fire) per asset, and assess vulnerabilities (e.g., unpatched servers) via group discussions and stakeholder interviews.
Patch deployment: Integrated into IT change management and project risk assessments; patches deployed promptly post-evaluation to mitigate high/medium risks, prioritizing based on likelihood (1-5 scale) x impact (1-5) scores.
Threat sources: Internal reviews, external changes (legislation, breaches), standards (ISO 27002/17/18), and supplier evaluations. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We use AWS Tools (Inspector, GuardDuty, Detective), GitHub Dependabot, Coralogix & Datadog for monitoring of logs, privileged access, failures and anomalies.
Real time threat detection via GuardDuty/Detective, vulnerability scans via Inspector/Dependabot, and SIEM alerts identify unauthorised access or exploits.
As soon as we're made aware of any compromise/incident our Incident Response Plan activates to contain, eradicate and recover the threat, or escalate via our Business Continuity & Disaster Recovery Policy.
Our response times for multi-user outage are under 1 hour acknowledgement and 24 hours resolve. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Hackajob's Incident Management Policy (within ISMS) defines processes for detection, reporting, assessment, prioritization (High/Medium/Low via impact on assets/business), response, and recovery—via Flowchart and Procedure. Users report incidents immediately to IT Service Desk/CTO per procedure. Reports use Notion's Incident Tracking Document (timeline, actions, impact) linked in a dedicated Slack channel. Internal comms via Slack; external (customers, regulators, media) by IMT with pre-written statements, legal review, and logs for compliance.
Customers can report incidents via support email/ticketing. We provide incident updates and a post-incident report (including root cause and corrective actions) for material incidents - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Hackajob can provide a trial of the service, without limitations, up to 30-days or until a hire is made.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Accorp Partners Cert Inc.
- ISO/IEC 27001 accreditation date
- Thursday 24 April 2025
- What the ISO/IEC 27001 doesn’t cover
-
Hackajob’s ISO/IEC 27001 certification covers the Information Security Management System (ISMS) scope defined for hackajob Ltd, including the infrastructure, applications and systems used to deliver our services, and the activities and business functions that hold, obtain, share or manage customer and business data.
Items not covered are those outside this ISMS scope, including:
Customer-controlled environments and configurations (for example, the customer’s ATS, user devices/endpoints, networks, and identity provider/SSO configuration).
Third-party systems or services not operated or controlled by hackajob, except to the extent they are managed through our supplier risk management process.
Data, systems, or processes that sit outside hackajob Ltd’s audited scope (for example, customer internal processes, and any customer-side storage, exports, or onward sharing performed by the customer).
Security controls and processes that are the customer’s responsibility under the shared responsibility model (for example, user access administration and joiners/movers/leavers decisions). - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 Type 1
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-