Security
Your people's data, handled like it matters.
What's in place today, and — because we're in a private test — what isn't yet. Until the list below is done, please use sample data only.
In place
- Two-step sign-in
- Authenticator-app codes with backup codes. Owners can require it for admins, HR and payroll, or for everyone; people it applies to can't use anything else until it's set up.
- Roles and scope
- Seven roles — owner, admin, HR, payroll, manager, planner, employee — plus per-person grants. Managers and unit heads see their own reporting lines and sub-units, not the whole company.
- Private fields
- Personal email, date of birth, emergency contacts and similar fields are visible only to the person and HR.
- Tamper-evident audit log
- Every sensitive change is recorded with who, what and when. Each entry carries the SHA-256 hash of the previous one, so editing an old entry breaks the chain after it.
- Encrypted documents
- Uploaded files are encrypted with AES-256-GCM before they are stored, and file types are checked by their contents, not their names.
- Office-network rules
- Check-in and API access can be limited to your office's network addresses.
- Sessions and passwords
- Sessions end after 12 hours. Passwords need at least 10 characters, and sign-in attempts are rate limited.
- Signed webhooks
- Outgoing events are signed with HMAC-SHA256, sent only over HTTPS and never to private or internal addresses.
Not done yet
We'd rather tell you than have you find out. These come before anyone stores real records.
- An independent security review or penetration test
- Single sign-on (Okta, Azure AD, Google Workspace)
- Malware scanning of uploaded files
- Email delivery — notifications stay inside the app for now
- Written uptime, data-residency and response-time targets