How an Australian HR-technology SaaS provider replaced manual SQL exports of candidate and employee data with a least-privilege, encrypted, fully logged extract service — and gave its engineers their time back.
Data minimisation · least-privilege orchestration · encrypted delivery · complete audit trail
An Australian HR-technology company whose recruitment and onboarding SaaS platform is used by large employers to hire and manage people at scale. That means holding candidate and employee data for organisations that take security assessments seriously: enterprise procurement teams and government buyers who send long questionnaires and expect evidence, not assurances.
The platform runs across multiple AWS accounts. The internal team is small and product-focused, with limited specialist depth in database and network security, and it was scaling faster than its operating practices.
Sector: HR-technology SaaS (recruitment and onboarding) · Customers: large employers, enterprise and government · Platform: multi-account AWS · Engagement: Jul – Oct 2025
Customers needed repeatable data exports for analytics and compliance. Those were being produced with ad-hoc SQL and manual handling: personal information exposed on the way through, inconsistent filters, missed schedules, and engineers pulled off product work to run them. The business needed a secure, automated data-extract service with clear ownership and support — one it could show a customer or an auditor.
We designed the extract capability as a supported service and built the pattern underneath it:
Every export now answers the question an auditor asks first: who requested it, what was in it, and where did it go.
Data minimisation, purpose limitation and least privilege by default, with approval gates for sensitive datasets and transparent communication about limitations and trade-offs. Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it.
Under the Privacy Act and the contracts enterprise customers write, the business that holds personal information is accountable for every copy of it. An engineer running a query and emailing a spreadsheet is a copy nobody can account for. Turning that into a service with approvals, encryption and a log is unglamorous work, and it is the difference between a notifiable breach and a routine request.
Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.