Skip to main content
Mentum
Browse JobsCompaniesSalariesFor EmployersFor UniversitiesLog inSign up
Loading...
Loading...
Mentum

Transparent, skills-based job matching.

Browse JobsCompaniesSalariesFor EmployersFor UniversitiesLog inSign up

© 2026 Mentum. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyLegalTrust CentreAI TransparencyHelp CentreProduct updatesContact

Apprenticeship vacancies provided under the Open Government Licence v3.0. Contains public sector information.

On this page
Reading progress0%

    On this page

    Reading progress0%

      ← Back to Legal

      Modern Slavery and Anti-Bribery Statement

      Last reviewed 14 July 2026 · Next scheduled review 12 May 2027

      14 July 2026 update: removed the Coursera and Impact Tech rows from the sub-processor register (no data-flow relationship; removed 11 July 2026), recounted the supply-chain totals accordingly, and corrected the adversarial-test-layer count.

      Controller of record: Mentum. Contact: privacy@mentumjobs.com (data protection); dpo@mentumjobs.com (DPO routing); security@mentumjobs.com (modern-slavery and anti-bribery concerns; security reports); support@mentumjobs.com (operational, abuse, appeals).

      Regulatory anchors: UK Modern Slavery Act 2015 s. 54 (Transparency in Supply Chains); UK Bribery Act 2010 (ss. 1, 2, 6, 7 and the s. 7(2) “adequate procedures” defence); Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003 (Mentum platform employment context).

      Anchors: Privacy Policy; Terms of Service; Acceptable Use Policy; Data Processing Addendum; Sub-processor list; Data Retention Schedule.

      1. Statement of commitment

      Mentum is committed to operating its platform free of modern slavery, human trafficking, forced labour, and bribery in any form.

      This statement is published voluntarily. Mentum's turnover is below the £36 million threshold at section 54 of the Modern Slavery Act 2015, and Mentum is not required to publish a section 54 statement at this time. It is published because regulated-sector procurement teams (financial services, healthcare, public sector) routinely require one, and because the same posture supports the “adequate procedures” defence at section 7(2) of the Bribery Act 2010.

      The statement covers the financial period to date and is reviewed annually, or off-cycle if Mentum's headcount, supply chain, or processing activities change materially. The next scheduled review is 12 May 2027.

      2. Business structure

      Mentum is a sole-developer UK SaaS business at pre-launch stage, operating a job board with AI-assisted candidate–job matching.

      Mentum has:

      • no employees;
      • no contractors, agents, or “associated persons” within the meaning of section 8 of the Bribery Act 2010;
      • no physical premises beyond a single Windows workstation under operator control;
      • no subsidiaries or group entities;
      • no overseas operations.

      All operations — engineering, deployment, support, privacy response, and security review — are performed by one person. This sizes every other claim in this statement.

      3. Supply chain

      Mentum's “supply chain” is exclusively software-as-a-service vendors engaged via online sign-up flows. Mentum purchases no physical goods, retains no logistics or distribution partners, holds no inventory, and operates no premises requiring cleaning, security, catering, or maintenance services.

      The complete current supply chain is the public sub-processor list at /legal/subprocessors. At the date of this statement the list contains thirteen entries: Supabase, Google (Gemini API and Firebase Cloud Messaging), Twilio SendGrid, Railway, GitHub, Sentry, a Redis provider (operator-pending pinning), Adzuna, postcodes.io, Nominatim, the UK Department for Education's Apprenticeships Service, and ClamAV. (The complete list — which also enumerates the other inbound job-feed sources as a consolidated inbound-only row — is at the sub-processor list.)

      Of these, eleven are engaged sub-processors in the UK GDPR Article 28 sense. One (Nominatim) is a browser-direct hand-off and one (ClamAV) is an open-source library running locally — they are listed for transparency, not because they meet the Article 28 engagement test.

      4. Risk assessment

      4.1 Modern slavery and trafficking risk

      Mentum does not engage workers directly and does not purchase physical goods or services from sectors with elevated slavery or trafficking risk (agriculture, construction, hospitality, garment manufacture, electronics assembly).

      Residual upstream risk sits with the cloud-infrastructure operators that Mentum's sub-processors themselves depend on — Amazon Web Services, Google Cloud, and Microsoft Azure — and with the data-centre construction and hardware-component supply chains those operators consume. Mentum's leverage over that upstream risk is one degree removed: we choose sub-processors who publish their own Modern Slavery Act statements and supplier-conduct expectations, and we record their attestation status in our internal vendor matrix.

      A second risk surface sits on the platform itself: job listings that advertise illegal work arrangements or carry modern-slavery indicators. This is addressed in § 5 below via the Acceptable Use Policy.

      4.2 Bribery Act 2010 risk

      As a sole-operator pre-launch business with no procurement programme, no public-sector tenders won to date, no overseas operations, and no agents or associated persons acting on Mentum's behalf, the inherent bribery risk under sections 1, 2, and 6 of the Act is low. The section 7 corporate offence (failure to prevent bribery by an associated person) is the residual surface; at the date of this statement Mentum has no associated persons within the section 8 definition.

      This assessment will be reconsidered if Mentum engages sales agents, channel partners, contractors, or wins a public-sector tender. At that point the controls in § 5 will be expanded to include the specific gifts, hospitality, and facilitation-payment controls a section 7(2) “adequate procedures” defence requires.

      5. Policies and due diligence

      5.1 Policies in force

      • Acceptable Use Policy (/legal/aup §§ 4.1 and 4.3) prohibits any job listing that advertises or facilitates modern slavery, forced labour, trafficking, right-to-work fraud, unpaid trial shifts of unreasonable duration, or pay-to-apply / training-bond schemes that fall outside the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003. Listings are subject to takedown and account closure on violation.
      • No gifts, hospitality, or facilitation-payments programme. Mentum does not offer, solicit, or accept gifts, hospitality, or any form of facilitation payment in connection with platform business. Should that posture change (for example, on engagement of a sales agent), a Bribery Act 2010 section 7(2)-compliant gifts-and-hospitality policy will be drafted and published before the activity begins.
      • Vendor selection criterion. New sub-processors are evaluated against published attestations (SOC 2 Type 2, ISO 27001, where applicable HIPAA / FedRAMP) and, where the vendor publishes one, a current Modern Slavery Act statement.

      5.2 Sub-processor Modern Slavery Act statements

      The following table is Mentum's current view of which sub-processors publish a Modern Slavery Act statement, either directly or via a parent company. It is the operating evidence behind the § 5.1 vendor-selection criterion.

      Sub-processorStatusStatement sourceLatest dated
      Google LLCPublishes own statement2024 Google Statement Against Modern Slavery2025 (covering FY2024)
      Twilio SendGrid Inc.Covered under parent (Twilio Inc. / Twilio UK Limited)Twilio UK Modern Slavery Statement, available via investors.twilio.comFY2023 statement (published May 2024)
      GitHub, Inc.Covered under parent (Microsoft)GitHub Statement Against Modern Slavery and Child Labor (Microsoft group statement applies)Current
      Adzuna LtdNot required (below £36M turnover threshold based on public filings)n/an/a
      Supabase Inc.Not currently publishedEngagement criterion limited to SOC 2 / ISO 27001 / HIPAA attestations; revisit annuallyn/a
      Railway CorpNot currently publishedEngagement criterion limited to SOC 2 Type 2 attestation; revisit annuallyn/a
      Functional Software, Inc. (Sentry)Not currently publishedEngagement criterion limited to SOC 2 / ISO 27001 attestations; revisit annuallyn/a
      Redis providerPending pinningProvider-dependent; re-assess at provider-pinning pointn/a
      postcodes.io, Nominatim, UK Department for Education, ClamAVNot applicablePublic-data service, Crown body, or open-source libraryn/a

      Reading: of the seven commercial sub-processors that engage in identifiable upstream supply chains, four publish a current Modern Slavery Act statement (directly or via parent) and three do not currently publish one. Mentum's residual leverage on the latter three is limited to its choice to remain on the vendor, periodic re-assessment, and substitution if a comparable attested vendor becomes available.

      5.3 Due-diligence process

      Due diligence at vendor onboarding consists of:

      • reviewing the vendor's published security and privacy attestations;
      • verifying DPA availability and execution status;
      • checking the vendor's published Modern Slavery Act statement (where one exists);
      • recording the assessment in the internal vendor matrix, including risk scoring (criticality × likelihood), residency, and next-review date.

      The matrix is reviewed annually and on any material change. Mentum does not operate an annual on-site supplier audit programme, mandate a contractual supplier code of conduct as a precondition of every engagement, or operate a third-party whistleblowing hotline service. These controls are disproportionate to a single-operator pre-launch business and are not claimed.

      6. Training

      Mentum has one operator, who is self-trained.

      No formal classroom or e-learning programme exists. The operator's training record is the in-repository compliance work itself: the SOC 2 / ISO 27001:2022 readiness assessment, the GDPR audit history (73 findings closed across 11 batches), the eleven in-repository adversarial test layers covering OWASP-aligned attack surfaces, and the Architecture Decision Records.

      This posture is recorded as an accepted residual risk in the readiness assessment, with a defined trigger to revisit: headcount exceeding one. At that point a written induction covering this statement, the Acceptable Use Policy, and the Bribery Act 2010 will be required of every new starter.

      7. Reporting concerns

      Concerns about modern slavery, trafficking, forced labour, or bribery — whether on the Mentum platform, within Mentum's supply chain, or in dealings with Mentum — may be raised by emailing security@mentumjobs.com.

      Reports are read by the operator; there is no separate intake team. Reports may be made anonymously; a return address is helpful but not required.

      • Where a concern relates specifically to a job listing or user conduct on the platform, the same channel applies and the matter will also be handled under the Acceptable Use Policy §§ 4.1 and 4.3.
      • Where a concern relates to personal data, the appropriate channel is privacy@mentumjobs.com, or dpo@mentumjobs.com for formal data-protection rights requests.
      • Where a concern relates to a suspected criminal offence under the Modern Slavery Act 2015 or Bribery Act 2010, reporters should also consider contacting the Modern Slavery Helpline (08000 121 700) or the police directly; reporting to Mentum does not substitute for a report to the appropriate authority.

      Mentum commits to acknowledging substantive reports within five working days. Mentum will not retaliate against any person who raises a concern in good faith. Where a report identifies a substantiated breach by a sub-processor, Mentum's response options range from a request for remediation, to invocation of the sub-processor change procedure at § 7.4 of the Data Processing Agreement, to termination of the affected engagement.

      This statement is not voluntarily registered on the UK Government's Modern Slavery Statement Registry at this time; voluntary registration will be considered at the next annual review if a regulated-sector customer requires it.


      Related: Acceptable Use Policy | Sub-processor list | Data Processing Addendum | Data Retention Schedule | Privacy Policy | Terms of Service.