← All articles

Building the Data Layer for the Agentic Era


Our CTO, Max, on why staffing firms are becoming builders, what “secure by design” really means, and how objective candidate data cuts through the noise of AI-driven fraud.

Something is shifting in how staffing and recruitment firms buy and build technology. For years, the default was to license a CRM or an ATS off the shelf and adapt the business around it. Increasingly, our customers are doing the opposite: assembling bespoke, custom-built ecosystems tailored to how they actually work. We sat down with Max, PitchMe’s CTO, to talk about what that means for data, security, and the road ahead.

From mainframes to agentic CRM

Ask Max where this trend comes from and he frames it as the next chapter in a very old story. The industry has traveled from mainframes to personal computing to the cloud, and AI is simply the newest force lowering the barrier to entry. What used to require a dedicated engineering organization is now within reach of far more companies.

The practical consequence is that customers are no longer just users of software.  They are becoming the developers of their own systems, wiring together sourcing, enrichment, and candidate workflows to match their own playbook. That freedom is powerful, but it comes with new weight on the shoulders of teams that never set out to run a data platform.

“As customers build their own systems, they take on the complexity of data security, isolation, and regulation. That’s exactly where we come in.”

This is where PitchMe positions itself: as the data layer sitting between a customer’s systems and the many sources those systems draw from. Through open APIs and programmatic interfaces, PitchMe feeds the enrichment, candidate, and sourcing flows that customers are stitching together so they can focus on the workflow and let us handle the hard parts of the data underneath.

Security that’s built in, not bolted on

In a field where sensitive personal data is constantly in motion, security is never far from a customer’s mind, and Max is quick to say it shouldn’t be. PitchMe’s answer is to align with recognized standards, including GDPR, SOC II, and ISO, to work hand in hand with security auditors on an ongoing basis rather than treating compliance as a once-a-year exercise.

That means continuous attention to both infrastructure and code, so that customers relying on PitchMe’s APIs have a dependable foundation for their own data architecture. When your platform is the layer everything else is built on, trust isn’t a feature… it’s the product.

Store less, protect more

One of PitchMe’s more distinctive choices is philosophical as much as technical: minimize what is held at rest. Rather than accumulating large stores of candidate data, PitchMe works in real time, querying data sources and writing results back into the customer’s own systems.

The goal is to keep as little as possible in transit and to stay as close to the customer’s own databases as the technology allows. Less data sitting idle means a smaller surface to defend and a cleaner compliance posture.  An approach Max describes as unusual in the industry, and deliberately so.

One platform, many jurisdictions

PitchMe is a UK-incorporated company serving customers on both sides of the Atlantic, which raises an obvious question about data residency. The answer, Max explains, is to follow the regulations of whichever country the customer operates in and to treat residency as a configurable decision rather than a fixed constraint.

Global organizations often carry their own policies about where data may live and how it must be processed. By working with PitchMe, those customers can shape their data flows to satisfy exactly what their legal teams require, storing and processing in one location or another as the situation demands.

Security is a shared responsibility

None of this happens in isolation. System integrations are, by nature, a chain of participants, and Max is candid that security is a joint effort rather than any single vendor’s burden. PitchMe’s commitment is to be transparent and compliant about the portion of data processing it owns and to collaborate closely with customers and data suppliers, so the entire supply chain stays secure.

“Security is a joint effort. Our job is to be transparent and compliant on our part, and to work closely with everyone else on theirs.”

Objective data as an answer to AI fraud

The rise of AI has an uncomfortable flip side in recruitment: some candidates now use the same tools to impersonate, embellish, or outright defraud. Max sees it as a familiar arms race where both sides are adopting technology, for good and for bad.

PitchMe’s counter is not to fight AI with AI theatrics but to lean on something harder to fake: current, objective data drawn from independent sources. When a customer can validate a candidate’s claims against a neutral record, fraudulent applications become far easier to spot and dismiss, and the genuinely strong candidates rise to the top of the list where they belong.

What’s next: openness by design

Looking toward the end of the year, Max points to a clear theme in the roadmap: more flexibility for customers to integrate with the systems of their choice. As more firms build bespoke stacks across an increasingly complex landscape, PitchMe wants to be effortless to plug in.

That means investing in an open API for integration and MCP servers that let customers connect PitchMe directly into their own custom agents. The intent is simple, make PitchMe’s data flows a native part of the automations and AI workflows customers are already building, rather than another system they have to work around.


Max’s closing line doubles as a fitting summary of the whole conversation:

“Data has to be secure. There should be more data and it should be more secure.”


See how PitchMe protects your data

PitchMe.co

Discover more from PitchMe Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading