You hold people's careers. We treat it that way.
Candidate records are salaries, histories and personal details, some of the most sensitive data an agency touches. Here's exactly how Crumblelead protects it, and the tools we give you to stay on the right side of GDPR.
We're early, and we won't badge-wash. We don't have a SOC 2 report framed on the wall yet, formal certification comes as we grow. What we do have is real, in the product today, and everything on this page maps to how Crumblelead actually works. If you need specifics for a security review, ask and we'll answer plainly.
Encrypted coming, going, and sitting still
Encrypted in transit
Every request is served over TLS. Nothing moves between you and Crumblelead in the clear.
Encrypted at rest
Your data is stored on managed cloud infrastructure that encrypts data at rest.
Encrypted credentials
The tokens for your connected Gmail, Outlook and calendar accounts, and any SMTP passwords, are encrypted at the field level, separately from the rest of your data.
The right people, and only them
Two-factor authentication
Turn on TOTP two-factor from an authenticator app. Passwords are hashed with bcrypt, never stored in the clear.
Roles that mean something
Admin, Manager and Consultant roles decide who on your team can see and change what, enforced on every request, not just hidden in the UI.
Session control
Sign out, reset your password, and manage two-factor from your account settings whenever you need to.
Your database is walled off from everyone else's
Crumblelead is multi-tenant, but your data never mingles with another agency's. Every candidate, client and job is scoped to your team at the database layer, and middleware checks your team membership on every single request.
- ✓ No shared candidate or job pool, ever
- ✓ Team scoping enforced in the database, not just the interface
- ✓ A user can only ever reach data for teams they belong to
Compliance built into the workflow, not sold as an add-on
Most ATSs leave GDPR to you and a spreadsheet. Crumblelead ships the machinery: lawful basis, consent, and retention are part of how candidates move through the system.
Lawful basis, per candidate
Record why you hold each candidate, legitimate interest, consent, contractual necessity or legal obligation, the way the regulation actually asks you to.
Consent, tracked properly
Send candidates a secure link to agree or decline. Consent is captured with a timestamp and source, and every change is written to a consent log you can point to.
Retention that runs itself
Set a retention window and Crumblelead runs the clock, flagging records that are overdue and sending owners a quarterly review digest of what needs attention.
When a candidate exercises their rights, you're ready in a click
Subject Access Requests
One click builds a candidate’s full SAR export, a PDF summary, a JSON data dump, and every file on record, packaged as a ZIP, with the deadline tracked for you.
Right to erasure
Erasure isn’t a delete button. It removes files, anonymises the profile and parsed CV, redacts notes and the audit trail, and sends a completion confirmation with a reference number.
Leave with everything
Export candidates, clients, jobs and placements to CSV in one click, any time. Your data is always yours to take with you.
And every sensitive action, exports, deletions, changes, is written to an audit trail that's itself anonymised when a candidate is erased.
Your data is not our training data
We never train or fine-tune AI models on your candidates. Crumble AI runs on a third-party AI provider's API, and under that provider's terms, data sent through the API isn't used to train their models. Need the provider named in writing for your file? We'll put it in your DPA.
A short, vetted vendor list
We use a small number of vetted sub-processors to run the platform. We publish how they break down by function, what data each touches and where, and we share the full named list with customers under our DPA. We give 30 days' notice before adding a new one.
See our sub-processorsFound something? Tell us.
Email [email protected] with steps to reproduce. We acknowledge good-faith reports within one business day and we won't pursue legal action against researchers acting in good faith.
Docs for your review
Need a DPA or answers for a vendor security questionnaire? Reach out and we'll send what you need.
Handle candidate data like it matters
14 days, every feature, no card. Bring one client and see how the compliance tooling fits your desk.