Most high-volume recruitment platforms are bought on the strength of the demo, and the demo shows the wrong things. Buyers watch a chatbot book an interview, or a ranking engine sort ten thousand CVs before the coffee cools, and they sign. The parts that decide whether the platform survives a hiring surge or a breach never appear on the screen, and neither do the parts that decide how it fares in a lawsuit. Those parts are infrastructure. Eight of them matter more than any matching algorithm on the market, and the order below follows the damage each one does when it's missing.
Access control comes first, because the most instructive recruitment failure of recent years had nothing to do with artificial intelligence being clever or stupid. In the summer of 2025 two security researchers, drawn in by complaints about a fast-food chain's hiring chatbot, found an administrator login that accepted 123456 as both username and password. Behind that login sat a second flaw, where changing an applicant number by one pulled up somebody else's file, and the sequence covered more than 64 million job applications at McDonald's. Names, email addresses, phone numbers and chat histories were all reachable. The pair reported both flaws that evening, and the login stopped working less than two hours later.
Volume multiplies every lapse. A forgotten test account at a hundred-person firm might expose a few hundred applicants, while the same account inside a platform that hires for a national chain exposes a number of records approaching the population of the United Kingdom. So the first essential is the dull one. In practice it means retiring every shared or default login and putting a second login step on each administrative account. Record numbers should be impossible to guess as well. And every time a person opens a candidate file, the system should write that down, because the log is the only way to learn afterwards who looked.
The second essential concerns where candidate data lives and whose data sits beside it. Most recruitment software is sold as a shared service, with many employers' applicants held in the same systems and kept apart by the software's own rules. That arrangement is efficient and usually safe. Its weakness is that the separation depends on the code being right every single time, and in the McDonald's case one missing check exposed applicants across the chain's franchised restaurants at once.
Anyone pricing the alternative to a shared service can start with dedicated USA-based hosting from Atlantic.Net, which rents out physical servers that stand apart from any shared cloud platform, with full administrative control and a choice of five American data centres. For a job board or staffing firm holding large volumes of US applicant records, that kind of arrangement buys a short, checkable answer when a client's auditor asks where the files sit and who else runs software on the same machine. None of that fixes a weak password, which is why this item sits second and not first.
Third, and probably growing fastest, is fraud walking in through the front door. A 2025 survey of 3,000 job candidates found 6% admitting to interview fraud, either posing as someone else or having someone pose as them, and the analysts behind it predict that one in four candidate profiles worldwide will be fake by 2028. Treat the forecast with the scepticism any forecast deserves. The survey figure deserves less of it, since it comes from candidates describing their own behaviour. Here the argument of this column bends a little, because some of the strain on the pipes does come from AI after all, just from the applicant's side of the table. The same analysts advise checking at the level of the system rather than watching individual applicants, which means building identity verification and alerts for unusual patterns into the recruiting software itself.
A recent piece on this site made the sharper version of that point, arguing that employers should verify the candidate rather than police the writing on a CV. The point is sound, and acting on it changes the plumbing. Checks on identity and credentials have to move earlier in the process, so the platform must reach out to verification services at the moment of application without stalling under load. Both obvious places for that check carry a cost. An application form that demands a passport scan on page one will lose honest people, while a check left until the offer stage means interviewers may have spent whole afternoons on candidates who don't exist.
Fourth is capacity for the day everyone applies at once. High-volume hiring doesn't arrive evenly. Seasonal retail and graduate schemes with a closing date push most of their traffic into a few days, sometimes a few hours. A platform sized for an average Tuesday will stall on those days, and an applicant staring at a frozen page on a phone has every reason to try a competitor instead. The better designs accept and acknowledge an application at once, then leave the heavy scoring until the rush has passed. The irony is that the AI screening which sold the platform is often the most expensive thing to run at peak, and also the easiest part to postpone. Ask a vendor for results from a test at three times the busiest day on record, and notice how long the reply takes.
Fifth comes retention, which sounds like housekeeping until two legal systems pull in opposite directions. Federal rules in the United States require employers to keep application forms and other hiring records for a year from the later of the record's creation or the decision it concerns, and to hold everything relevant once a discrimination charge is filed until the matter is closed. Data protection law in Britain and Europe pushes the other way, toward deleting personal data once there's no longer a reason to hold it. A platform serving employers on both sides of the Atlantic needs deletion clocks that differ by country, along with a way to freeze one applicant's file for a dispute without freezing everyone else's. A single global purge setting is likely to break one law or the other.
Agencies were advised on this site to set retention periods for candidate data as far back as 2017, while the GDPR was still on its way. The advice has aged well, but advice isn't a mechanism. So ask the vendor to show the scheduled job that deletes expired records, the log it writes each time it runs, and what happens to a file that has been frozen for a dispute. A vendor who needs a week to find those answers is probably deleting by hand, if at all.
Sixth, the platform needs a record of what its software decided and why. When a screening model turns away forty thousand applicants in a week, somebody will eventually ask how, and it may well be a regulator. New York City has required independent bias audits of automated hiring tools since 2023, and a December 2025 review by the state comptroller found the city's enforcement of that rule weak. Employers shouldn't read that as comfort, because lax enforcement is often followed by a period of catching up. Each automated decision should carry the model version and score that produced it, plus any human override, kept for as long as the hiring record itself.
Seventh is the least discussed item on the list and, day to day, one of the most irritating. High-volume hiring runs on text messages and email, for interview invitations and shift offers above all. Mobile networks and the big mailbox providers have spent the past few years tightening the rules on bulk senders, and messages from senders who haven't registered or proved their identity properly are increasingly filtered or refused. A candidate who never receives an interview invitation doesn't complain. That candidate simply fails to appear, and the recruiter marks a no-show against a name that never had a chance. Somebody should own the sender registrations the way somebody owns the company's domain name.
Eighth, and last for a reason that may seem perverse, is monitoring. Monitoring prevents nothing on its own. All it does is shorten the gap between a failure and the moment someone notices. Without it, though, none of the seven items above can be checked in practice, so the last entry on the list is the one that tells you whether the other seven are really there. The questions for recruitment system suppliers that this site published in 2013 still make a decent agenda for a first meeting, starting with when an outside firm last tried to break in and what the system does if one data centre goes dark.
Put the eight side by side and an awkward pattern shows. The people who choose recruitment platforms usually sit in talent acquisition. The people who could answer these questions tend to sit in IT and legal, several meetings away from the demo. Two curious outsiders needed a job application and a few hours to find what the people running the McDonald's hiring system had apparently missed. Who in your organisation has actually logged into your hiring platform's admin screen, and would they know if the password were 123456?

