Why we've introduced passkeys to our whole platform

Why we've introduced passkeys to our whole platform

People who apply for jobs through our platform hand over a lot of personal information: names, addresses, work histories, contact details. They do it trusting that it will be kept safe, and the agencies who run their recruitment with us are trusting us with the same thing.

That information is also why recruitment platforms get targeted. A candidate database is a useful starting point for identity theft, so we treat protecting it as part of the core job rather than a box to tick. We've recently changed how everyone signs in, and it's worth explaining what we did and why.

The trouble with passwords

Passwords have guarded online accounts for decades, and over the same period they've been the weak point in most serious data breaches.

Most people reuse the same password across different sites, so a leak somewhere else can expose accounts everywhere. Passwords can also be guessed, bought in bulk after other companies are breached, or captured by a convincing fake login page. That last one, phishing, catches out careful and experienced people all the time. Telling users to pick something stronger doesn't fix a system where the secret can be copied or tricked out of them in the first place.

We didn't want that weakness sitting anywhere near the data we hold.

What we changed

Everyone now signs in with a passkey. That covers the recruitment websites, the job boards and the CRM that agencies work in every day, and it applies to candidates, recruiters and administrators alike.

Passkeys are the login standard backed by Apple, Google, Microsoft and the wider security industry. We've built them in across the board rather than offering them as an optional extra on one screen.

How a passkey works

A passkey stays on your own device, whether that's your phone, laptop or a hardware key, and you unlock it the way you already unlock the device: with a fingerprint, your face or a PIN.

There's no password to type and nothing shared with the website that could be stolen later. Because a passkey only works on the genuine site it was set up for, a fake login page has nothing to capture and won't work anyway. And since each passkey is unique to our platform, a breach on some other service can't spill over onto us.

Why we did it across everything

A platform is only as secure as its weakest way in. A strong candidate login paired with a softer back-office door doesn't solve the problem, it just moves it somewhere less visible.

So we applied the same standard to every account, from a candidate registering for a role to an administrator with the deepest access of all. There's no easier entrance to find round the back.

What it means for the people who use it

Candidates get solid protection for the information they share when they apply, plus an easier sign-in with no password to remember or reset.

Agencies and the businesses running on our platform can point to a security standard that holds up to scrutiny, whether that's from clients, from candidates or from regulators, all of whom are paying closer attention to how personal data is handled. It's a genuine difference you can stand behind.

Day to day, signing in is quicker and the account behind it is much harder to break into. Better security and less hassle at the same time, which doesn't happen often.

Where this leaves the sector

We think security belongs in the foundations rather than sold on as an upgrade, and it should cover a whole platform rather than the one screen customers happen to see. So we looked at what other vendors are doing. Across the recruitment technology providers we checked, none offer passkey sign-in at all: not on candidate registration, not on the login page. As far as we can tell we're the first to bring it to the whole platform, and we plan to stay there.

The people who trust us with their data shouldn't have to think about any of this. Good security is something you feel the benefit of without noticing, and that's what we've aimed for on every sign-in.

If your website is not helping your agency, it is time to replace it with one that does

Book a 20-minute demo. We'll walk the platform live and show exactly how Nodex would work for your agency.

  • Tell us about your agency A few details so the demo is relevant, not generic.
  • We reply within one business day A real person from the team, not an automated drip.
  • Walk the platform together Live demo, honest pricing, clear next steps. No obligation.

Prefer to talk now? Call 01260 734 107.

From £189/month. No long-term lock-in. Your data stays yours.