Industries · Recruitment
Candidate trust, at the volume you hold it.
We built and operate Restart Recruitment’s systems, and handle the same class of candidate data in production.
A recruitment agency holds more personal information per employee than almost any business its size: resumes, identity documents, work rights, salary expectations, and the candid notes between them. Most of it sits in SaaS (an ATS, a CRM, an outreach tool), and clients increasingly ask hard questions about all of it before they will send a brief.
We built Restart Recruitment’s candidate intake, screening and scorecard flows, and its outreach engine, and we handle the same class of data in systems we run, with eleven invariant tests pinning TOTP replay, OAuth timing, and signing caps so a later change cannot quietly regress them.
What you carry, and what we do about it.
Candidate PII at volume, and the Privacy Act’s employee-records exemption does not cover job applicants.
We map the data you hold and where it lives, and review the gaps against the Australian Privacy Principles.
Privacy Act / APP upliftClient security questionnaires decide whether you get the brief, and they ask about the SaaS stack you run on.
A posture assessment maps where you stand against recognised controls, and SMB1001 readiness turns the answers into a certification you can point at.
Security posture assessmentRecruiters live in email and act fast: exactly the behaviour account-takeover and payroll-redirection scams exploit.
Controlled phishing campaigns measure how the team behaves under a well-crafted pretext, and a tenant identity review closes the paths a captured credential would use.
Phishing & social-engineering simulationThe stack itself (intake, screening, outreach) has to hold the line without slowing the desk down.
We built Restart’s: candidate intake, scorecard screening, and the outreach engine, with eleven invariant tests pinning TOTP replay, OAuth timing, and signing caps.
See the Restart build
The obligations in play
- Privacy Act 1988
- Candidate personal information sits squarely under the APPs: the employee-records exemption does not extend to applicants.
- Notifiable Data Breaches scheme
- A breach of candidate data likely to cause serious harm must be assessed and notified.
- Labour hire licensing
- Queensland, Victoria, and South Australia license labour-hire providers, with conduct and reporting conditions attached.
- Spam Act 2003
- Outreach at volume must respect consent, identification, and unsubscribe rules.
Not legal advice; your advisers own the interpretation.
Built and running
Restart Recruitment
An executive and senior-specialist search business. We built the brand, the site, the candidate intake, screening and scorecard flows, and the outreach engine, with eleven invariant tests pinning the security model: TOTP replay, OAuth timing, signing caps.
See the workThe services behind this work.
Defensive & advisory
Ongoing security leadership for organisations that need somebody to own cyber risk but do not require a full-time CISO.
Read more
Compliance readiness
Black Shard works with organisations preparing for the Essential Eight, SMB1001 and ISO 27001, as well as businesses reviewing their obligations under the Australian Privacy Principles.
Read more
Software engineering
We design, build and operate applications, internal systems and cloud infrastructure for Australian businesses.
Read more
Answer the questionnaire with evidence.
Brisbane head office. Work delivered across Australia.

