Security at HR Instance
Your employee data deserves enterprise-grade protection. Here's exactly how we secure it.
AES-256 Encryption
All data at rest is encrypted with AES-256. Sensitive tokens use AES-256-GCM with unique per-record IVs โ the same standard used by banks.
TLS 1.3 in Transit
All communication between your browser and our servers uses TLS 1.3 โ the most secure transport protocol available.
Two-Factor Authentication
Admins can enable TOTP-based 2FA for all accounts. We support Google Authenticator, Authy, and any TOTP-compatible app.
Audit Logs
Every action in the system is logged with actor ID, timestamp, IP address, and action type. Full audit trail available for enterprise plans.
Data Residency in India
All customer data is stored on AWS servers in Mumbai, India (ap-south-1). Your data never leaves Indian jurisdiction.
Role-Based Access Control
Granular RBAC ensures employees only access what they're authorised to see โ by module, by action, and by department.
Regular Security Audits
We conduct annual third-party penetration testing and internal security reviews. Issues found are patched within 48 hours.
Responsible Disclosure
We have a vulnerability disclosure program. Researchers who report issues responsibly are acknowledged and rewarded.
Found a Security Vulnerability?
We operate a responsible disclosure program. Please notify us privately before any public disclosure.
Report a Vulnerability