Security and privacy

Your people data, kept to itself

Passports, salaries, bank details and medical files all sit in one system. Nathan HRMS gives every organisation its own database, hides the fields a role has no business seeing, and records every change.

  • A database of your own
  • Encrypted in transit and at rest
  • Field-level access control
  • Hosted in the EU
CLIENT DATA SEPARATION

Separated by the database,
not by a line of code.

Most HR platforms put every customer in the same tables and tell them apart with an identifier column. We give each organisation a database of its own.

MOST HR PLATFORMSOne table, every companyemployeescompany_idOne query that forgets its filter reads another company's rows.NATHAN HRMSOne database per companyYOUCLIENTCLIENTCLIENTA query cannot reach data that is not in the database it connected to.

ENCRYPTION AND SIGN-IN

Encrypted in transit, at rest,
and again on top.

Every connection to your data is verified before it carries anything, and passwords are never stored at all.

TLS on every connectionEncryption at restAES-256-GCM on credentialsYOUR RECORDS

Every connection

TLS enforced, with invalid certificates and invalid host names both rejected. An unverified connection is never accepted.

Data at rest

Managed cloud encryption at rest, with automated backup and point-in-time recovery.

Stored credentials

Integration keys and connection secrets are encrypted with AES-256-GCM, so they are never held in readable form.

Passwords and passcodes

Never stored. Hashed with bcrypt at cost factor 12 and excluded from query results by default, so they cannot be returned by accident.

Documents and files

Served only through signed links that expire, issued to an authenticated user. There is no public URL for a client document.

ACCOUNTABILITY

Permissions tell you who can.
Audit tells you who did.

Sensitive data needs more than access control. It needs the ability to show, afterwards, exactly what happened.

Audit logATTRIBUTABLER. Haddad updated SalaryRecorded centrally09:14You granted Payroll accessRecorded centrally08:52S. Menon viewed Passport scanRecorded centrallyYesterdayA. Iqbal deleted Contract v2Recoverable, trail intactMonNothing is written without a name and a timestamp against it.
01.

Audit log

An attributable record of data changes, who changed what and when, captured centrally rather than feature by feature.

02.

Activity and session tracking

User activity and active sessions are visible to your administrators, so an unexpected session can be spotted and ended.

03.

Non-destructive deletion

Deletion keeps the record recoverable and the audit trail intact, instead of quietly discarding both.

04.

Request and notification logs

A per-organisation record of handled requests, and proof of whether a policy or payslip actually reached someone.

HOSTING AND RESIDENCY

Your people data stays in the European Union.

Nathan HRMS runs on managed cloud infrastructure in Frankfurt, Germany, with your documents in storage dedicated to your organisation.

  • Production runs in EU data centres in Frankfurt, Germany, across two availability zones.
  • Managed database platform with encryption at rest, automated backup and point-in-time recovery.
  • Databases answer only to approved addresses, with separate credentials per environment.
  • Releases roll out without downtime and roll back on their own if health checks fail.

Our information security management system is aligned to ISO/IEC 27001 and ISO/IEC 42001 for AI governance, with SOC 2 Type II certification in progress. HRMS gives you the field-level control, audit trail and residency that UAE PDPL and EU GDPR programmes depend on.

EUROPEAN UNIONAvailability zone AServing trafficAvailability zone BServing trafficEncrypted at restBacked up, recoverableFrankfurt, GermanyYour people data does not leave the EU.
SECURITY FAQ

What reviewers ask before they sign.

If your security team needs more than this, we complete questionnaires and hold architecture calls as part of procurement.

Talk to our team

DUE DILIGENCE

Bring your security team. We expect the questions.

We complete security questionnaires, discuss architecture with your information-security function and support due diligence requests as part of procurement.