Security & data handling
Honest overview of how we protect your data.
Authentication
Passwords are hashed. Sessions use secure cookies. Email verification and password reset use time-limited tokens.
Encryption
All traffic is encrypted in transit (HTTPS). Data at rest is stored on infrastructure with standard provider encryption.
Access control
Your organisation's data is isolated. Only authenticated users in your organisation can access your employees and certificates.
Documents
Uploaded files are stored privately, not in public URLs. We validate file types and size limits.
What we don't claim
We do not claim SOC 2, ISO certifications, or "bank-level" security unless explicitly obtained and documented. We focus on sensible practices for a small business SaaS product.
Report a concern
Email bluehammy122@gmail.com if you discover a security issue.