Skip to content
EmployeeSight

Security & compliance

The boring details, written honestly.

What we’ve already done, what we’re in the middle of, and what’s on the roadmap — without “enterprise-grade” doing any heavy lifting.

01 · Data encryption

At rest. In transit. Always.

Active

All customer data is encrypted at rest with AES-256, and all connections use TLS 1.3 (1.2 minimum). Database backups are encrypted with separate keys, rotated quarterly. Secrets live in AWS KMS or GCP KMS depending on the customer’s region.

  • AES-256 at rest
  • TLS 1.3 in transit
  • Quarterly key rotation
  • Hardware-backed key storage
02 · Data residency

Where the data lives.

Active

All customer data is hosted in Mumbai (AWS ap-south-1). Data does not leave the region unless you explicitly enable a cross-region report export. We do not use US-region hosting for any customer.

  • Mumbai (ap-south-1) · India default
  • AWS ap-south-1 · single region
  • No US-region hosting. Mumbai only.
  • Regional failover within the same region
03 · Access controls

Who can see what.

Active

Role-based permissions for HR admin, finance, manager, and employee, each with a baseline visibility scope. Single sign-on via Google and Microsoft on the Platform plan; SAML 2.0 and SCIM provisioning on Enterprise. Every administrative action lands in an immutable audit log exportable to your SIEM.

  • Four default roles + custom on Platform
  • Google + Microsoft SSO (Platform)
  • SAML 2.0 + SCIM (Enterprise)
  • Audit log exportable to SIEM
04 · Compliance posture

What we have. What's underway.

India’s DPDP Act 2023 — compliant since launch; the DPA documents every obligation. SOC 2 Type II audit is in progress — target close FY 2025-26. ISO 27001 is on the roadmap behind SOC 2. We won’t claim certifications we don’t hold.

  • DPDP Act 2023 · today
  • SOC 2 Type II · in progress (target FY 25-26)
  • ISO 27001 · roadmap
  • DPA available on request and at /legal/dpa
05 · Vulnerability response

Disclosure, fast.

Active

Critical vulnerabilities get an emergency patch within 24 hours. We run continuous dependency scanning (Snyk + GitHub Advanced Security) and quarterly third-party penetration tests. Bug reports to sales@employeesight.com earn a real response, not a robot reply.

  • 24-hour critical patch SLA
  • Continuous dependency scanning
  • Quarterly third-party pentest
  • Coordinated disclosure window
06 · Employee privacy in Work

Privacy is the product.

Active

The Workforce product ships with screenshots off by default, keystrokes never captured, and a per-employee private-hours toggle that produces zero records. The full posture is on the Work product page.

  • Screenshots off by default
  • Keystrokes never logged
  • Private hours produce no records
  • Per-employee opt-out

Stop juggling tools. Start seeing your team.

14-day beta access · No card required · Workspace ready in 1 business day