Skip to content

Security & Privacy

Your most sensitive data, encrypted per organisation and kept in the EU.

Salary data deserves more than a privacy policy. Field level encryption with per organisation keys, EU only processing, anonymisation in every analysis, and an audit record for every change.

30 minutes. Bring your security team and their questions.

Your most sensitive data, encrypted per organisation and kept in the EU.
How your data is protected

Concrete architecture, not reassurance.

Encryption

Encrypted at the field, keyed per organisation

Names, personal information, salary data and performance data are encrypted at field level with AES-256-GCM. Envelope encryption is backed by Google Cloud KMS with a separate key per organisation and support for rotation, so one customer's key never touches another customer's data.

  • Field level AES-256-GCM on all sensitive employee data
  • Per organisation keys in Google Cloud KMS, rotation supported
  • Decryption purpose logging, so access has a reason attached
Talk to us about the architecture
EU residency

Nothing leaves the EU

Infrastructure runs in the Finland region, and AI processing happens inside the EU in the Netherlands. There is no transfer of your data outside the EU, and customer data is never used to train models.

  • Infrastructure in the Finland region
  • AI processing inside the EU, never used for model training
  • Minimal risk classification under the EU AI Act
See how the AI is governed
Privacy by default

GDPR built into the product, not bolted on

Right to erasure with secure overwrite, data export, data minimisation and decryption purpose logging are product features. Every analysis applies anonymisation thresholds, so small groups are suppressed automatically and no individual can be identified from an aggregate.

  • Right to erasure with secure overwrite, and data export
  • Anonymisation thresholds suppress small groups everywhere
  • Data minimisation as a default rather than a setting
Read our privacy policy
Access and audit

Every change has a name against it

Access is capability based across 55 distinct capabilities, with role based assignment and organisation membership validated on every request. The audit log records who changed what and when, with old and new values, IP address and user agent.

  • Capability based permissions, validated per request
  • Audit log with old and new values, IP and user agent
  • Information security management system established January 2026
Ask for our security documentation

Defence in depth

Layers that assume any single control can fail.

01

Edge protection

Web application firewall and DDoS protection in front of the application.

02

Request hardening

Rate limiting and security headers applied across the surface.

03

Continuous scanning

Static analysis and dependency scanning run on every change.

04

Review before merge

Security review on every change, assisted by automated analysis.

Common questions from security teams

Infrastructure runs in the Finland region and AI processing happens inside the EU, in the Netherlands. Your data does not leave the EU, and it is never used to train models.

Ready to put this in front of your security team?

We will walk through the architecture with them, in detail.