Candidate protection
Candidate identity, contact details and exact location stay hidden until the controlled introduction process allows release.
South African proof-first talent platform
TALLO separates candidate and client workflows into secure portal experiences. Candidates build proof-backed profiles. Clients browse anonymous approved talent. Operations access is restricted and not advertised publicly.
Profile, assessments, proof, availability and intro consent.
Anonymous talent discovery, shortlisting and controlled introductions.
Locked access model
Each area is intentionally separate. A candidate should not see the client workspace. A client should not see operational controls.
Build your anonymous TALLO profile, add proof signals, complete assessments and respond to introduction requests.
Open candidate portal ClientBrowse approved anonymous candidates, review proof, request controlled intros and manage hiring activity.
Open client portalProduct model
The platform is not being built as one messy interface with role-specific tabs. It is being shaped as separate applications that share the same secure backend and database.
This keeps the product simple for non-technical users, easier to secure, easier to explain to clients, and stronger for future investor or acquisition due diligence.
Phase focus
Candidate identity, contact details and exact location stay hidden until the controlled introduction process allows release.
Employer accounts do not automatically browse the marketplace. Approval is part of the trust layer.
Review, moderation and risk handling stay away from candidate and client workspaces.
Important user and client actions are timestamped so the platform can defend commercial claims, disputes and compliance questions.
No vanity screens. Every dashboard element must help a user make a better hiring decision or complete a required action.
Role checks belong on the server. The interface is only the front door, not the permission system.
Security posture
Candidate and client users enter through different locked workspaces.
Private API routes must validate identity, role, status and resource ownership.
Clients see only anonymous candidate cards until the consent and declaration process is complete.
Profile changes, intro requests and prior-contact declarations are audit events.
Build roadmap