Industries · Recruitment
Candidate trust, at the volume you hold it.
We run a recruitment business ourselves, so the data, the questionnaires, and the inbox risk are problems we already solve for Restart Recruitment.
A recruitment agency holds more personal information per employee than almost any business its size: resumes, identity documents, work rights, salary expectations, and the candid notes between them. Most of it sits in SaaS (an ATS, a CRM, an outreach tool), and clients increasingly ask hard questions about all of it before they will send a brief.
We hold the same data ourselves. Restart Recruitment is our own executive-search venture, and we built its candidate intake, screening and scorecard flows, and its outreach engine, with eleven invariant tests pinning the security model so a later change cannot quietly regress it.
What you carry, and what we do about it.
Candidate PII at volume, and the Privacy Act’s employee-records exemption does not cover job applicants.
We map the data you hold and where it lives, review the gaps against the Australian Privacy Principles, and make the fixes practical rather than theoretical.
Privacy Act / APP upliftClient security questionnaires decide whether you get the brief, and they ask about the SaaS stack you run on.
A posture assessment maps where you stand against recognised controls, and SMB1001 readiness turns the answers into a certification you can point at. We hold SMB1001:2026 Gold ourselves.
Security posture assessmentRecruiters live in email and act fast: exactly the behaviour account-takeover and payroll-redirection scams exploit.
Controlled phishing campaigns measure how the team actually behaves under a well-crafted pretext, and a tenant identity review closes the paths a captured credential would use.
Phishing & social-engineering simulationThe stack itself (intake, screening, outreach) has to hold the line without slowing the desk down.
We built Restart’s: candidate intake, scorecard screening, and the outreach engine, with eleven invariant tests pinning TOTP replay, OAuth timing, and signing caps.
See the Restart build
The obligations in play
- Privacy Act 1988
- Candidate personal information sits squarely under the APPs: the employee-records exemption does not extend to applicants.
- Notifiable Data Breaches scheme
- A breach of candidate data likely to cause serious harm must be assessed and notified.
- Labour hire licensing
- Queensland, Victoria, and South Australia license labour-hire providers, with conduct and reporting conditions attached.
- Spam Act 2003
- Outreach at volume must respect consent, identification, and unsubscribe rules.
This list orients the engineering work. It is not legal advice; your advisers own the interpretation.
The build behind this page
Restart Recruitment
Our own executive and senior-specialist search venture. We built the brand, the site, the candidate intake, screening and scorecard flows, and the outreach engine, with eleven invariant tests pinning the security model: TOTP replay, OAuth timing, signing caps.
See the workThe services behind this page.
Defensive & advisory
Ongoing security leadership and review, without hiring a full-time CISO.
Read more
Compliance readiness
Get audit-ready against the frameworks Australian businesses are actually asked for.
Read more
Software engineering
Engineering for the systems a business runs on: web, native mobile, portals, and the platform underneath.
Read more
Answer the questionnaire. Win the brief.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

