Security, privacy, and a compliance roadmap you can verify
Current safeguards, data-processing documents, sub-processors, and the milestones in our SOC 2 Type II program.
Key facts
Hosting
AWS us-east-1 (multi-AZ)
Encryption of stored data
AES-256 (RDS, S3, EBS)
Encryption of data in transit
TLS 1.2+ everywhere
Audit log retention
7 days (Free) / 1 year (Starter+) / 3 years (Pro+)
GDPR data subject rights
Export · Erasure · Rectification (admin UI)
Data residency
us-east-1 today; EU + APAC on Enterprise (2027)
Backup
Daily snapshots, 30-day retention
Uptime target (goal, not a guarantee)
99.95% (Multi-AZ AWS)
Documents + commitments
Regulatory posture
Our compliance program tracks the regulatory landscape that affects workforce-management data: GDPR (EU), CCPA/CPRA (California), PIPL (China for offshore SMBs with mainland workforce), and the usual ISO / SOC 2 industry baselines.
Got a security questionnaire?
We respond to vendor due-diligence requests within 3 business days, including CAIQ-Lite + custom forms. Send the form, get a signed response.
