Case studies · Recruiting & staffing
How We Found and Closed 3 Real Security Gaps in a Live Platform Handling Candidate PII for a Recruiting Technology Platform
A full access-control audit moved candidate data protection from "looks right on screen" to enforced at the data layer.
How we did it
- Step 1Full Access Audit
Audited actual data-access rules, not just the interface.
- Step 2Server-Enforced Shielding
Replaced front-end-only masking with real server-side enforcement.
- Step 3Scoped Access Tokens
Every sensitive route now requires a scoped, expiring token.
- Step 43 Gaps Closed
A shielding bypass, an open admin gap, and unauthenticated routes — all fixed.
Consent-First PII Shield
Tokenized disclosure of personal data with consent gates.
See Consent-First PII Shield, from $347
Not sure it fits? The free Business Checkup shows what’s costing you money and what to fix first.
More results like this
Client names are withheld by default and replaced with an industry description throughout — the work speaks for itself either way.