TalentLink - ATS, Recruitment & Onboarding for Public Sector
TalentLink is a configurable Applicant Tracking System supporting end-to-end recruitment: job approvals, posting, social integration, career sites, and AI-driven, unbiased job matching. Design custom applications, anonymise candidates, manage shortlisting, assessments, interviews, offers, contracts, and onboarding. Out-of-the-box integrations include Broadbean, Enboarder, and DocuSign for job distribution, AI onboarding, compliance, document signing.
Features
- Applicant tracking, recruitment, campaign and requisition & approval management
- Job distribution and job board posting
- Career sites, configurable application processes & CV parsing
- Talent Pooling, pipeline management & candidate search and match
- Manager Self Service including dedicated dashboards & online short-listing
- Interview management, Offer & contract generation
- Creation of engaging pre and on-boarding experiences
- Interactive recruitment metric dashboards and ad-hoc reporting
- Anonymous Application management
- Integrations for job distribution, assessment, and e-signatures
Benefits
- Accelerates recruitment with streamlined, configurable applicant tracking workflows.
- Improves candidate experience from application through onboarding stages.
- Reduces time-to-hire by automating key recruitment processes.
- Supports compliance and audit readiness for Public Sector hiring standards.
- Enhances workforce diversity through fair, transparent recruitment practices.
- Optimises talent selection with data-driven insights and assessments.
- Increases retention by enabling effective onboarding and engagement strategies.
- Minimises administrative burden with integrated communication and scheduling tools.
- Strengthens employer branding with customisable career sites and messages.
- Facilitates workforce planning by linking hiring data to strategic goals.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 7 2 1 6 2 3 2 5 6 2 3 5 7
Contact
SQEPTECH LTD
Roberta King
Telephone: +447734112102
Email: roberta.king@sqeptech.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Stand alone or integrated with other Cornerstone modules and other systems.
Full Integration with the Cornerstone Suite, which can seamlessly tie employee learning and performance metrics to give executives and managers a clear picture of how learning initiatives impact organisational success.
Full integration with eSQEP Competency Management & Assurance app. - Cloud deployment model
- Public cloud
- Service constraints
- No, Cornerstone is a Software-as-a-Service. Users can access the application at any time and from anywhere through the internet. In addition, SQEPtech has broad experience in developing highly stable single sign-on linkages with its clients. End users will be able to access the infrastructure seamlessly with one login and from a specified location on the client’s network.
- System requirements
-
- As a SaaS Service - there are no hardware requirements.
- Minimum Desktop Requirements: Recommendations upon request
- Supports Mobile Device Enablement: Recommendations upon request
- There are no software maintenance, and no network administration requirements
- Access to internet connectivity as the solution is SaaS/Cloud based
- Safari, Google Chrome, Firefox, IE11 and above
User support
- Email or online ticketing support
- Yes
- Support response times
-
Business working hours Mon-Friday 9.00 - 17.00; slower response during the weekend.
Typical support responses times:
• Priority 1 – 1 working day
• Priority 2 – 3 working days
• Priority 3 – 10 working days - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Customers can contact the SQEPtech support team via support@sqeptech.com indicating issues and their estimated level of priority as follows:
• Priority 1 – fail in operations
• Priority 2 – reported bug or issue without a workaround in place
• Priority 3 – reported bug or issue with a workaround in place
SQEPtech will endeavour to apply fixes to the reported issues in line with the reviewed priority level as follows:
• Priority 1 – 1 working day
• Priority 2 – 3 working days
• Priority 3 – 10 working days
Managed services support level can be put in place, costs varying on number of payslips required to be produced on a monthly basis.
Account Manager and/or Client Success Support available depending on type of contract. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Once the contract has been executed, SQEPtech will assign the client a dedicated Implementation Consultant. The Implementation Consultant will be the primary point of contact during implementation. In addition, they will be supported by a project team as appropriate to the scope of work. This may include a Program Sponsor, Engagement Manager, Integration Consultant, and Training Consultant.
We deploy our solution in significantly less time than required for similar deployments of legacy software. Our SaaS model eliminates the need for complex technical requirements such as code customisation, equipment deployment, and unique delivery models.
A typical implementation takes approximately 6-8 weeks for an initial module based on scope and complexity.
With years of experience and hundreds of deliveries across various industries, we’ve learned what it takes to ensure our clients can make a successful leap to impact.
Our Cornerstone University Services team provides consulting, training, and performance support tools to enable clients to learn and use our talent management solutions successfully. We offer a blended training approach to accommodate different learning styles.
This approach is designed to meet individual learning needs, whether the trainee has five minutes or five days. The self-regulated learning approach supports heavy interaction or independent learning. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- In the event that a client does not renew their contract, we will return the client’s data via their secure FTP site in the same format in which the data was originally inputted into the software. Alternatively, the client’s data can be returned in a mutually agreed format at a scope and price to be agreed. We will maintain a copy of the client data for no more than six months following termination of the agreement, after which time any client data not retrieved will be destroyed.
- End-of-contract process
-
Our agreements are for a term lease period, and software fees are paid in annual installments over that period, during which time SQEPtech recovers costs. Accordingly, during that lease period (as with, say, a rental or car lease), there can be no termination for convenience.
Effect of Termination: Immediately following termination of this Agreement, Client shall cease using all Products. Client may retrieve Client Data any time prior to termination or expiration of the Agreement. If requested, SQEPtech will assist with such data retrieval at a scope and price to be agreed. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Cornerstone Mobile allows users to view their learning transcript and to download, view, and interact with rich, standards-based courseware and knowledge content from their smartphones and tablet devices. Content conforms to SCORM 1.2, SCORM 2004, and AICC standards and is supported for maximum content interoperability and reusability.
Our offline player allows users to complete online courses on their phones and tablets while not connected to the internet. Online classes behave as though they are being used online: bookmarks are kept, progress is saved, etc. After reconnecting to the internet, the results of the training can then be uploaded to Cornerstone. - Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
Cornerstone has available a number of out-of-the-box API’s as functionality exposed as web services. Currently, four main areas of functionality are offered through our web services.
User and Organisational Unit upload / Edit
a) A feed from your HRIS or system of record can upload and modify new users, Organisational Units and changes.
Transcript and Task retrieval
a) Ability to see the homepage widgets and user transcript
b) Home page widgets available:
Assigned Training In Progress Upcoming Sessions Pending Tasks
c) Also available: View of the entire user transcript
Sections within the curricula available for viewing
d) Web service provides status and IDs for learning objects
Catalog Search
a) Ability to search the catalog by title, description, etc., to see training and sessions available to a given user
Learning Objects
a) Ability to perform general functionality for learning objects
b) Tasks available:
Request
Register
Launch Materials
Complete
Creation and updates of Goals
The web services are a configuration. Cornerstone provides the web service URL and documentation to the client. All the necessary information is provided in the documentation. The client will use standard web service API’s on any platform or any tool that supports web services to consume ours. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Cornerstone provides unique flexibility in how G Cloud clients can deploy the system to different groups of users. Customisation in the form of different branding, business rules, and functionality can be established for any Organisational Unit (such as Division, Location, Position, custom group of individuals, etc.). The end result is an unparalleled level of personalisation for the user.
Cornerstone was designed to be administered by the client and not the vendor. G Cloud Clients have complete control to configure the look and feel of the application to your specific business units with specific functionality and branding. Client administrators are presented with an extensive set of web-based controls which enable them to easily configure graphics, colors, key words, layout, and business rules.
Clients can make configuration changes on their own without any assistance from Cornerstone or for any additional costs. Not all vendors can make this claim. The high configurability of the Cornerstone system is one of the distinct advantages that we offer to our customers.
Scaling
- Independence of resources
-
The Cornerstone application, as per the Software as a Service model, is designed to scale horizontally. It is multi-tenant-efficient, offering a load balanced farm of identical instances known as swim lanes. When additional server equipment is added, the application capacity scales to fill the available hardware.This allows virtually unlimited growth capacity.
As opposed to a classical behind the firewall or hosted architecture, our application and our hardware platforms are designed to:
• Efficiently support a high number of users and customers
• Redistribute load easily
• Add additional capacity easily and quickly
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Cornerstone’s SLA guarantees 99.5% uptime (excluding reasonable and scheduled maintenance periods) per month.
Support is enabled for named client administrators to access Global Care knowledge assets, solutions, and self-service support tools online at any time. This is powered by a case management system and interface that provides the ability to submit, update, track and manage questions, issues, and other requests. - Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Cornerstone OnDemand
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Other
- Other data at rest protection approach
- For customers that elect to add an additional layer of encryption at rest onto their contract, Cornerstone offers the ability to encrypt database files using AES-256 encryption. The SQL Server database files are encrypted using Microsoft’s Transparent Data Encryption (TDE) technology. The keys used to encrypt the databases are stored on NIST/DOD FIPS 140-2 certified USB storage keys or through a hardware security module (HSM).
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Clients can export their data at any time through our reporting engine and analytics tool. In addition, an outbound data feed can be established from Cornerstone to an internal client system such as a data warehouse.
Cornerstone does offer data warehouse replication services. A client’s entire Data Warehouse is replicated to a separate server in our data center to allow clients to make direct SQL connections over a Virtual Private Network (VPN). Clients can report against all data in the replicated data warehouse directly without having to use our Analytics module. - Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- TLS (Version 1.2 or above), VPN, restricted access (SSO) and dedicated lines.
Availability and resilience
- Guaranteed availability
-
Cornerstone provides an SLA for all clients that guarantees initial response and resolution in regards to defined priority and severity levels.
Cornerstone’s SLA also guarantees 99.5% uptime (excluding reasonable and scheduled maintenance periods) per month. - Approach to resilience
-
Cornerstone’s Disaster Recovery/Business Continuity Plan defines plans, procedures, and guidelines for the Company in the event of disaster. Specifically, this document establishes procedures for recovering business operations, internal data; systems, and critical internal functions to maintain Cornerstone as an on-going concern in the face of unexpected events.
The plan has the following primary objectives:
•Identify critical systems, services, and staff necessary to maintain and/or restore Cornerstone business operations and internal functions.
•Provide guidelines for the communication of activities and status to both Cornerstone staff and client personnel during the recovery period.
•Present an orderly course of action for restoring critical computing capability to Cornerstone and for maintaining and/or restoring client service and support.
Cornerstone performs site-to-site replication of data to protect client data in the event of a disaster. There are two dedicated disaster recovery sites distant from each of the production data centers. Disaster recovery testing is performed semi-annually at each DR site. - Outage reporting
-
Outages occur during scheduled maintenance/releases. Otherwise, the system is not likely to experience any outages, however in the unlikely event of an unexpected outage, clients will receive email alerts.
Downtime is scheduled for planned quarterly releases at least 4 months in advance and deployed during off-peak hours, typically 8:30PM EST Fridays to 1AM EST Saturday (4.5 hours). Patch fixes typically occur every two weeks between 8:30PM EST and 12:00AM EST. The typical downtime for a patch deployment is approximately 10 minutes.
Client administrators can access a calendar of upcoming release and patch dates at any time through our client portal, Success Center. In addition, multiple email reminders are sent in advance.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
-
Users need a unique username, password to access the application. Alternatively, clients can be authenticated using security tokens, utilising a symmetric algorithm, passed by the client’s local authenticator for Single Sign-On functionality.
Passwords represent a fundamental and significant security mechanism at Cornerstone. Passwords are required to access the production network (via Active Directory) and applications (SQL Server). User accounts are created that employ individual user ID and passwords to identify and authenticate a given user. Users cannot access any Cornerstone system without a valid user ID and password. The SQL server logon groups are each configured to use Windows authentication. - Access restrictions in management interfaces and support channels
-
Users need a unique username, password to access the application. Alternatively, clients can be authenticated using security tokens, utilising a symmetric algorithm, passed by the client’s local authenticator for Single Sign-On functionality.
Passwords represent a fundamental and significant security mechanism at Cornerstone. Passwords are required to access the production network (via Active Directory) and applications (SQL Server). User accounts are created that employ individual user ID and passwords to identify and authenticate a given user. Users cannot access any Cornerstone system without a valid user ID and password. The SQL server logon groups are each configured to use Windows authentication. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Username or password
- Other
- Description of management access authentication
-
Users need a unique username, password to access the application. Alternatively, clients can be authenticated using security tokens, utilising a symmetric algorithm, passed by the client’s local authenticator for Single Sign-On functionality.
Passwords represent a fundamental and significant security mechanism at Cornerstone. Passwords are required to access the production network (via Active Directory) and applications (SQL Server). User accounts are created that employ individual user ID and passwords to identify and authenticate a given user. Users cannot access any Cornerstone system without a valid user ID and password. The SQL server logon groups are each configured to use Windows authentication.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
-
Cornerstone’s security procedures and controls provide assurance that processes maintain the confidentiality, integrity and availability of data for our customers. The policies and procedures cover the breadth and depth of IT operations, and infusing security by design through these processes. The information security policy and procedures apply to all Cornerstone employees, consultants, and contractors; and is intended to safeguard data and information technology for Cornerstone. Cornerstone does not publish these documents. However we can provide a secure online account, where you can access and view.Upon joining Cornerstone, applicable security policies and procedures are assigned to personnel to complete within a period of time. In addition, personnel complete updated training every year to ensure they understand and review the policies.
There is a dedicated IT Security & Compliance department, overseen by the CISO, that drive security oversight and initiatives across the organizations. Security responsibilities are also shared with the IT operations team that perform the day-to-day processes, and overseen by the CISO, who works in concert with our AVP of Technology Operations and Chief Technology Officer. The CISO is responsible for securing information in accordance with industry best practices and for implementing the recommendations of the various 3rd party audits - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- As a SaaS company, we release software frequently and regularly so that our clients may benefit from our on-going R&D. Cornerstone follows a defined SDLC (Software Development Lifecycle) that contains a number of important quality steps, an abridged version of which can be provided upon request. Development and Project Management are tasked with ensuring that these steps are followed.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Cornerstone contracts independent CREST-certified third parties to run external penetration tests on a quarterly basis. Additionally, monthly external vulnerability scans validate both the patch level and protection from known attacks. Results are provided to Cornerstone IT personnel for review and remediation. There are also various RSS feeds that Cornerstone is subscribed to, including US-CERT, the National Vulnerability Database (NVD), and vendor specific feeds for major software / hardware that Cornerstone uses within the environment. Clients can access the patch schedule at any time through our client portal, the Client Success Center. Clients can request copies of penetration reports as needed.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Quarterly application penetration tests are performed by independent third-party companies upon Cornerstone’s application. Cornerstone performs internal vulnerability scanning on a monthly basis. Internal and external penetration test is performed yearly by an independent third-party company.
Cornerstone has implemented a specific Data Breach Incident Management SOP which details the procedures to be followed in the event of a data breach.
Cornerstone has never had a security breach. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Cornerstone maintains a Security Incident Response Plan in order to organize resources to respond in an effective and efficient manner to an adverse event related to the safety and security of a computer resource under Cornerstone’s management. An adverse event may be malicious code attack, unauthorized access to Cornerstone managed networks or systems, unauthorized utilization of Cornerstone services, denial of service attack, or general misuse of systems. The plan clearly defines the appropriate steps and processes in communication. Clients will be notified within 24 hours of security incidents impacting their data.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 69e6f95f-dbf8-401d-b4f8-cee5d471e62a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-