Security & Trust Center

Enterprise security engineered into every layer.

Employee personal information, compensation benchmarks, and bank details require uncompromising security. We treat your workforce data with zero trust.

View Workspace Security Controls
Certified & AuditedAnnual Report

SOC-2 Type II

Annual rigorous audit covering Security, Confidentiality, and Processing Integrity by independent CPA auditors.

Audited 2026
CertifiedGlobal Standard

ISO/IEC 27001

International gold standard for Information Security Management Systems (ISMS) across all infrastructure.

Audited 2026
Fully CompliantData Privacy

GDPR & CCPA Compliant

Full support for Data Subject Access Requests (DSAR), right-to-be-forgotten workflows, and standard contractual clauses.

Audited 2026
BAA AvailableHealthcare

HIPAA Ready

Engineered to safeguard Protected Health Information (PHI) within medical leave and insurance document vaulting.

Audited 2026
Architecture Fundamentals

Built on a Zero-Trust Foundation.

Continuous verification, strict least privilege, and hardware-level isolation.

Cryptographic Protection

All databases, backups, and document attachments are sealed with customer-isolated AES-256 keys. TLS 1.3 with HSTS enforced for all traffic.

Strict Identity & Access (RBAC)

Enforce mandatory WebAuthn/TOTP two-factor authentication, SAML 2.0 Single Sign-On (Okta, Azure AD), and field-level permission masks.

Immutable Audit Trails

Every record creation, modification, export, or document download produces a cryptographically chained, immutable audit event with actor, timestamp, and IP.

Isolated Multi-Tenant Architecture

Logical and physical separation of tenant data prevents cross-contamination. Dedicated single-tenant VPC options available for Enterprise tier.

Data Sovereignty

Store your employee records where you do business.

Meet statutory data residency mandates across North America, the European Union, the United Kingdom, and Asia-Pacific with isolated regional database pinning.

US Region (Virginia / Oregon)
FedRAMP Ready Data Centers
EU Region (Frankfurt / Dublin)
Strict GDPR Sovereignty
UK Region (London)
UK-GDPR & DPA Compliant
APAC Region (Singapore / Sydney)
APEC Privacy Framework
Live Security Posture Telemetry100% Posture Score
Mandatory Two-Factor Authentication Enforced
Zero Unpatched CVE Vulnerabilities
Automated Daily Disaster Recovery Snapshots
Annual External Third-Party Penetration Test
99.99% Core API Uptime Over Last 12 Months