Skip to content

Security and compliance

Candidate data: one record, one chain of custody

Candidate and employee data in most recruitment businesses is decentralised: the CRM, the ATS, consultants’ inboxes, spreadsheets, job board exports and personal devices each hold a copy, and nobody can say where all of it is. That makes subject access requests slow, retention rules unenforceable, breaches wider than they should be, and AI governance impossible, because a model cannot be governed against data nobody has inventoried. Hexploits consolidates candidate data into a single governed record with a chain of custody: where each record came from, who has touched it, what it is being used for, and when it will be deleted.

A named engineer replies within one working day. A written scope and an indicative price within two.

  • Agencies and RPOs with candidate data spread across CRM, inboxes, spreadsheets and job boards.
  • HR software vendors whose customers ask where their candidates’ data goes.
  • Data protection officers handling subject access requests by searching mailboxes.
  • Firms preparing for EU AI Act or ISO 42001 work that keeps stalling on the question of what data exists.

Deliverables, not slogans. Each one appears in the statement of work.

  • A data inventory: every system, export and device that holds candidate data, with owner, purpose and lawful basis.
  • A single candidate record, integrated with the CRM and ATS you already run, with every source recorded against the fields it supplied.
  • A chain of custody on each record: origin, every access and change, every use including by AI, and the deletion date, in an immutable log.
  • Retention enforced by the system: records deleted or anonymised on schedule, with written confirmation.
  • Subject access and erasure requests answered from the record in hours rather than from mailboxes in weeks.
  • Access by named accounts and role, so a leaver’s access ends the day they leave.

Our engineers work across the major languages, frameworks and cloud platforms. We build on the stack you already run, with technology choices explained in writing before work begins.

The same four stages as every Hexploits engagement, applied to this capability.

  1. Stage 1

    Discovery

    Two to four weeks. We find where candidate data lives, how it got there, and what the retention and access rules say against what actually happens. Output: the inventory, a target model and a fixed figure or capped estimate.

  2. Stage 2

    Build

    The governed record and the integrations that feed it, migration of existing data with its provenance recorded, and retention and access rules built into the platform.

  3. Stage 3

    Launch

    Parallel running with the existing systems, a reconciliation of records between them, then cutover team by team with the old copies retired and their deletion confirmed.

  4. Stage 4

    Operate

    Retention runs, access reviews and subject access reporting produced on a schedule under deployment and monitoring.

One record from many sources: JobVantage and Gradvisor

JobVantage brings candidate and role data from specialist providers, CVs, voice notes and documents into one structured, scored record with the provenance of every field. Gradvisor, a UK careers charity, moved from a failing platform to one rebuilt in eight weeks with its data migrated intact. Both are the same discipline this page describes: one record, known origin, enforced retention.

Every engagement agrees its measures and the measurement period in writing before work starts.

  • Time to answer a subject access request, measured before and after.
  • Number of systems and locations holding candidate data, before and after.
  • Records past their retention date, reported monthly and trending to zero.
  • Share of candidate data with a complete chain of custody.

Case studies with numbers, and reviews linked to Google where they were left there.

  • Director, JobVantage

    Working with Hexploits has genuinely been a pleasure, and I see them as my scaling partner for the foreseeable future as JobVantage grows. If you’re looking for a development team who combine strong AI/engineering capability with honesty, flexibility and a real interest in your business, I’d strongly recommend them.

    Brandon BowdenDirector, JobVantageRead the review
  • Director, Gradvisor

    Fantastic company and our development partner for Gradvisor, a social mobility careers platform with national ambitions. Extremely responsive and mission-oriented. Cameron owns any shortfalls humbly - rare for IT providers. Thinks like a client too.

    Tushar PrabhuDirector, GradvisorRead the review
What is a chain of custody for data?
A record of where a piece of data came from, every system and person that has held or changed it, every purpose it has been used for, and when it was deleted, kept in a log that cannot be edited. It is what lets you answer a regulator, a candidate or an auditor with evidence rather than a search of mailboxes.
Why does decentralised candidate data matter for AI?
Because the EU AI Act and ISO 42001 both require you to know what data an AI system was trained on and is used with, and to test it for bias. If candidate data lives in a dozen places with no inventory, none of that can be evidenced. Consolidating the data is the first step of AI governance, not a separate project.
How long should we keep candidate data?
Long enough for the purpose and no longer, under UK GDPR. Many agencies settle on a defined period after last meaningful contact, with consent to keep in touch beyond it. The point is that the system enforces whatever period you set, rather than relying on someone remembering.
Do we have to replace our CRM?
No. The governed record integrates with the CRM and ATS you already run and becomes the source of truth behind them. What changes is that the inbox, the spreadsheet and the personal device stop being places where candidate data lives.
What about data on consultants’ personal devices?
It is inventoried, migrated into the governed record with its provenance, and then removed, with the removal confirmed. Going forward, access is through named accounts on managed devices, so the copies do not come back.

Request a proposal.

Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.