Skip to content

Security

Your people's data, handled like it matters.

What's in place today, and — because we're in a private test — what isn't yet. Until the list below is done, please use sample data only.

Audit entries, each linked to the previous one by its hashleave.approved09:12 · previous 0000…0000a41f…09c2person.updated09:14 · previous a41f…09c27be0…d51asecurity.two_step_policy09:20 · previous 7be0…d51ac93d…2f7einvoice.issued09:31 · previous c93d…2f7e1e58…b6a4

In place

Two-step sign-in
Authenticator-app codes with backup codes. Owners can require it for admins, HR and payroll, or for everyone; people it applies to can't use anything else until it's set up.
Roles and scope
Seven roles — owner, admin, HR, payroll, manager, planner, employee — plus per-person grants. Managers and unit heads see their own reporting lines and sub-units, not the whole company.
Private fields
Personal email, date of birth, emergency contacts and similar fields are visible only to the person and HR.
Tamper-evident audit log
Every sensitive change is recorded with who, what and when. Each entry carries the SHA-256 hash of the previous one, so editing an old entry breaks the chain after it.
Encrypted documents
Uploaded files are encrypted with AES-256-GCM before they are stored, and file types are checked by their contents, not their names.
Office-network rules
Check-in and API access can be limited to your office's network addresses.
Sessions and passwords
Sessions end after 12 hours. Passwords need at least 10 characters, and sign-in attempts are rate limited.
Signed webhooks
Outgoing events are signed with HMAC-SHA256, sent only over HTTPS and never to private or internal addresses.

Not done yet

We'd rather tell you than have you find out. These come before anyone stores real records.

  • An independent security review or penetration test
  • Single sign-on (Okta, Azure AD, Google Workspace)
  • Malware scanning of uploaded files
  • Email delivery — notifications stay inside the app for now
  • Written uptime, data-residency and response-time targets