Security

Your staff and payroll data, handled carefully

StaffHub holds attendance, salaries and statutory records. The controls below are how we keep those records correct, private and defensible.

Controls built into the product

Tenant isolation in the database

Every table enforces row-level policies scoped to your merchant account, so one organisation's records can never be read by another — even if a request is crafted by hand.

Role-scoped access

Staff, manager, admin and payroll maker/checker/approver roles are stored separately from profiles and checked server-side. Managers can only act within their own reporting subtree and outlets.

Immutable financial records

Invoices and payslips are rendered from snapshots frozen at creation. Re-downloading an old document always reproduces the original figures.

Append-only audit trails

Roster changes, approvals, overrides, salary revisions and payroll actions are written to audit logs that cannot be edited or deleted from the application.

Approval integrity

Self-approval of leave, regularisation and payroll actions is blocked at the database level, and decided requests are frozen once actioned.

Managed, encrypted infrastructure

Data is stored in a managed Postgres platform with encryption in transit, authenticated sessions and secrets kept out of the browser.

Reporting a vulnerability

If you believe you have found a security issue, email us with the details and steps to reproduce. We investigate every report and will keep you updated on the outcome.

Questions from your IT team?

Tell us what you need to review and we'll walk you through it.