Discreet candidate handling
Registration is reviewed before representation. Candidate details are not sprayed across the market or used as filler for speculative shortlists.
Emba supports sensitive hiring, advisory and delivery work. Trust here is not a slogan: it is how we shortlist, communicate, automate and decide what should never be automated.
Emba keeps the public experience simple while maintaining strong internal boundaries around candidate information, commercial context and automation.
Registration is reviewed before representation. Candidate details are not sprayed across the market or used as filler for speculative shortlists.
Cloudflare protections, security headers, rate limits, Turnstile and access controls protect the public edge. Internal drift checks monitor the stack.
Automation helps with triage, reminders, reports and ledgers. External submissions, invoices, pay runs and client-facing commitments stay behind a human gate.
Public forms ask for enough to start a useful conversation. Sensitive identity, payroll and clearance material is not collected through public webpages.
For regulated work, Emba treats client requirements, security expectations and official information handling as part of the operating model, not an afterthought. The Government ICT capability pack summarises this posture for procurement teams.
Health checks watch site availability, edge configuration, mail posture, candidate portal controls and business-system drift so issues are visible early.
Candidate registration does not authorise blanket submission. Emba reviews fit and context before any client conversation.
The website is not a channel for TFNs, bank details, clearance numbers, police checks or identity documents.
Drafting, reminders and operational checks can be automated. Sending, submitting, signing, invoicing and pay-run posting require approval.
Emba describes the controls it actually runs. Formal certifications or legal determinations are only claimed when they are real and current.
If you believe you have found a vulnerability affecting Emba systems, contact hello@emba.au. The canonical security contact is published at /.well-known/security.txt.
This page is intentionally plain. It avoids over-claiming and reflects current operating principles rather than a formal certification statement.