Skip to content

Security & Privacy

Your most sensitive data, encrypted per organisation and kept in the EU.

Salary data deserves more than a privacy policy. Field level encryption with per organisation keys, EU only processing, anonymisation in every analysis, and an audit record for every change.

45 minutes. Bring your security team and their questions.

Your most sensitive data, encrypted per organisation and kept in the EU.
How your data is protected

Concrete architecture, not reassurance.

Encryption

Encrypted at the field, keyed per organisation

Names, personal information, salary data and performance data are encrypted at field level with AES-256-GCM. Envelope encryption is backed by Google Cloud KMS with a separate key per organisation, so one customer's key never touches another customer's data.

  • Field level AES-256-GCM on all sensitive employee data
  • A separate Google Cloud KMS key for every organisation
  • Salary, personal and performance data unreadable without the organisation's key
Talk to us about the architecture
EU residency

Nothing leaves the EU

Infrastructure runs in the Finland region, and AI processing happens inside the EU in the Netherlands. There is no transfer of your data outside the EU, and customer data is never used to train models.

  • Infrastructure in the Finland region
  • AI processing inside the EU, never used for model training
  • Minimal risk classification under the EU AI Act
See how the AI is governed
Privacy by default

GDPR built into the product, not bolted on

Right to erasure and per employee data export are product features, and the sensitive fields are stored only as ciphertext. Every analysis applies anonymisation thresholds, so small groups are suppressed automatically and no individual can be identified from an aggregate.

  • Right to erasure and employee level data export
  • Anonymisation thresholds suppress small groups everywhere
  • Data minimisation as a default rather than a setting
Read our privacy policy
Access and audit

Every change has a name against it

Every screen and action is gated by a named capability, assigned through roles, with organisation membership validated on every request. The audit log records who changed what and when, with old and new values, IP address and user agent, and it is a screen in the product: your administrators can search it, filter it by person, entity or period, and export it for an auditor.

  • Capability based permissions, validated per request
  • Searchable, exportable audit log with old and new values, IP and user agent
  • ISO 27001:2022 certified, certificate available in our Trust Center
Open the Trust Center

Defence in depth

Layers that assume any single control can fail.

01

Edge protection

Web application firewall and DDoS protection in front of the application.

02

Request hardening

Rate limiting and security headers applied across the surface.

03

Continuous scanning

Static analysis and dependency scanning run on every change.

04

Review before merge

Security review on every change, assisted by automated analysis, inside an ISO 27001:2022 certified management system.

Common questions from security teams

Infrastructure runs in the Finland region and AI processing happens inside the EU, in the Netherlands. Your data does not leave the EU, and it is never used to train models.

Ready to put this in front of your security team?

We will walk through the architecture with them, in detail.