A recruitment ATS security review should establish who can access candidate data, how the supplier protects it and what happens when something goes wrong. Ask for evidence, test ordinary user permissions and agree the exit process before uploading the agency's database.
Recruitment records contain more than CVs. Notes can include salary expectations, contact details and sensitive context from conversations. A system that handles these records needs scrutiny even when the agency itself is small.
The aim is a proportionate buying decision. You do not need to become a security engineer, but you do need answers that mean something beyond “we take security seriously”. This checklist draws on the UK National Cyber Security Centre's cloud guidance, checked on 24 September 2026.
What evidence should a vendor provide?
Separate a statement from evidence about the statement. A supplier can describe a control accurately without holding an independent certification. Equally, a certification logo does not tell you whether its scope covers the exact service you are buying.
The comparison below shows how to move from a broad assurance to a useful procurement question. It is an assessment framework reviewed in September 2026, not a rating of individual vendors.
| Supplier statement | More useful evidence | Remaining question |
|---|---|---|
| Data is encrypted | Description of protection in transit and at rest | How are credentials and encryption keys protected? |
| Access is controlled | Roles, authorisation design and a restricted-user demonstration | Does the same boundary apply through integrations? |
| The service is audited | Current report, scope, period and exceptions where available | Does it cover the service and controls you rely on? |
| Backups are available | Recovery objectives and evidence of restoration testing | What could be lost and how long could recovery take? |
| You own your data | Export process, sample files and exit terms | Can you retrieve attachments and linked history? |
Record missing answers and give the supplier a chance to provide evidence. Keep unresolved requirements visible in the decision.
Who can sign in, and what can they see?
Ask how accounts are created, protected and removed. Two-factor authentication helps protect sign-in, but it does not replace permissions inside the product. A securely authenticated user can still have more access than their job requires.
Test with a consultant account. Check what that person can open, change and export, then repeat with a manager. Do not accept a demonstration performed entirely as the account owner as proof that restrictions work for everybody else.
Crumblelead supports TOTP two-factor authentication and stores password hashes using bcrypt. Its Admin, Manager and Consultant roles are enforced on every request. Agency data is scoped to its team at the database layer.
Those are specific controls, not a claim that every possible security question is answered. Your agency still needs a process for removing access when people leave and reviewing who has administrative authority.
How is information protected in transit and at rest?
Ask about data moving between your browser and the service, stored records, attachments and connected account credentials. “Encrypted” is a starting point; it should lead to a description of what is protected and where.
Crumblelead uses TLS in transit and encryption at rest. Connected email and calendar credentials are encrypted at field level. This matters because access to a connected mailbox or calendar is a separate exposure from access to one candidate record.
For any supplier, request the supporting security documentation and ask who can administer the underlying systems. If hosting location or international transfers affect your procurement requirements, establish those separately. An encryption statement does not establish a hosting jurisdiction.
What happens when AI or an integration is connected?
An integration can become another route into the same information. Ask whether it uses the recruiter's existing permissions or a powerful shared credential, and how you remove that access when it is no longer needed.
For an AI service, distinguish model training from other data handling. A no-training commitment does not, by itself, answer questions about processing locations, retention or which providers receive information. Read the applicable terms and the supplier's sub-processor information.
Crumblelead does not use candidate data to train AI models, and its AI provider's API terms do not allow training on the data sent through it. Its MCP connection respects the user's role, accesses only their team's data and uses a key that can be revoked at any time.
If you connect an external AI client, assess that client's arrangements too. The ATS's permissions are one part of the workflow; your choice of connected application is another.
Can you establish what happened after a problem?
An audit trail should help answer a concrete question: who performed a sensitive action, and what action was recorded? Ask which events are covered, who can inspect them and how long the evidence remains available.
Crumblelead records sensitive actions in an audit trail. Ask for the event coverage and retention details needed for your review.
Incident response deserves its own discussion. Ask how the supplier contacts customers, who investigates a suspected incident and what information it can provide to help your agency respond. Request the contractual obligations as well as a general support address.
Do not confuse ordinary support response times with a security incident commitment. Crumblelead's founders answer support directly, with a median reply time of about four hours; that is not an incident response service level or a guaranteed recovery time.
What should you ask about outages and recovery?
Backups, availability and recovery are related but different. A backup may exist without establishing how quickly it can be restored. A service can also be reachable while a particular record or attachment is missing.
Ask for recovery time and recovery point objectives in plain language: how long might the service be unavailable, and how much recent work might need to be recovered by another route? Ask when restoration was last tested and what the test covered.
Ask us for recovery evidence if it is a buying requirement, and apply the same discipline to every shortlisted vendor.
What belongs in the privacy and exit review?
Ask for the data processing agreement and sub-processor list. Check the assistance available for access requests, retention and erasure, and make sure the responsibilities make sense for your agency. This is procurement guidance, not legal advice.
Crumblelead makes a DPA available, publishes its sub-processors and gives 30 days' notice before adding a new one. It provides candidate-level lawful basis records, consent requests with timestamped logs, retention windows and overdue review flags.
For exit, request a sample that represents your actual database. Basic CSV files are useful, but do not assume they contain every attachment, email or relationship. Crumblelead provides one-click CSV exports of candidates, clients, jobs and placements; assess any wider handover requirement separately.
How should you treat SOC 2?
Crumblelead does not have SOC 2 yet. We say that plainly because a buyer should not have to infer it from a row of security claims.
If your client contract or procurement policy requires a current SOC 2 report, that requirement should decide the matter unless your organisation formally accepts another form of evidence. A lower price does not override your own obligations.
Where a supplier has a report, request the appropriate details and review the scope, reporting period and exceptions. An independent assessment can provide valuable evidence, but it still needs to match the service and risks you are evaluating.
A final checklist for the purchasing decision
- Test sign-in protection and the permissions of a normal consultant.
- Obtain the security documentation, DPA and sub-processor information.
- Establish AI and integration access, data handling and revocation.
- Record incident contacts and the evidence available after a sensitive action.
- Confirm recovery arrangements and any required independent assurance.
- Test a representative export and document the exit terms.
Give each unanswered item an owner and a decision date. The result should be a buying decision supported by evidence, not a folder of brochures that nobody has read.
Where Crumblelead fits
Crumblelead suits perm-focused independent and small-to-mid agencies seeking a connected desk with defined roles, team-scoped data and practical privacy tools. Its security controls include TLS, encryption at rest and TOTP two-factor authentication, but it does not have SOC 2 yet.
It is not built for large temp or contract staffing firms needing timesheets, payroll or VMS integrations. Agencies with mandatory assurance requirements should establish that those requirements can be met before proceeding.
FAQ
Does encryption prove an ATS is secure?
No single control establishes that. Review access, operational practices, integrations and recovery evidence alongside encryption.
Should every recruiter have administrator access?
Give people the access required for their work and review exceptions. Test the ordinary consultant role before deciding that administrator rights are necessary.
Does Crumblelead have SOC 2?
No, Crumblelead does not have SOC 2 yet. If a current report is mandatory for your purchase, take that requirement into account.
Is an export also a backup?
An export can support your continuity and exit plans, but its usefulness depends on its contents and format. It does not establish the supplier's ability to restore the live service.
Sources
NCSC cloud security principles. Checked 24 September 2026.
https://www.ncsc.gov.uk/collection/cloud/the-cloud-security-principles
NCSC choosing a cloud provider. Checked 24 September 2026.
https://www.ncsc.gov.uk/collection/cloud/choosing-a-cloud-provider
ICO controller and processor contracts. Checked 24 September 2026.