Legal
Security
Last updated: May 9, 2026
Your tenant carries salary, identity, and statutory data. Here is what we do to protect it.
1. Encryption
- At rest: AES-256-GCM. Database column encryption for sensitive fields (PAN, Aadhaar, bank account). Authenticated tag verification on every read.
- In transit: TLS 1.3 minimum, modern cipher suites only. HSTS with includeSubDomains and preload.
- Backups: daily encrypted backups stored in a separate region within India.
2. Authentication
- JWT-based sessions with rotating refresh tokens.
- Tenant administrators can enforce strong passwords, 2FA, and SSO (Pro/Enterprise).
- Brute-force protection: progressive lockout after repeated failures, IP and email scoped.
- Service accounts use short-lived API tokens, scoped to specific endpoints.
3. Authorisation
Strict tenant isolation at the database row level — every query carries a tenant_id predicate. Role-based access within a tenant: Owner, HR, Manager, Employee, with optional custom roles on Enterprise.
4. Audit logs
Every state change in payroll, salary, leave, and access control is captured in an append-only audit log. Logs are retained for 7 years by default and exported to your auditor on demand.
5. Operational hygiene
- All employees go through background verification before getting production access.
- Production access is logged and reviewed quarterly.
- No credentials shared in chat or email — secrets manager only.
- Patches applied within 7 days for high-severity CVEs, 30 days for medium.
6. Incident response
We have a documented incident response process with a 4-hour acknowledgement target and 24-hour public-status update target. Material incidents trigger written notification to affected tenants within 72 hours.
7. Penetration testing
External penetration tests run annually with rotating vendors. The most recent report is available on request to Enterprise customers under NDA.
8. Compliance certifications
We are working towards ISO 27001:2022 and SOC 2 Type II in 2026. We are aligned with the DPDP Act 2023 today.
9. Reporting a vulnerability
Email [email protected] with details. We acknowledge within 4 hours and patch high-severity issues within 7 days. Responsible disclosure is appreciated; we run a private bug bounty for Enterprise customers.