Updated July 20, 2026
HRM runs businesses’ revenue, operations, people, and finance workflows — so the platform is built on the assumption that it will hold sensitive data and must prove what it did with it.
Every customer’s data is tenant-isolated with database row-level security enforced at the database role level — the application cannot query across tenants. Managed-service clients can be deployed on dedicated, single-tenant infrastructure. Management access to production runs through audited channels with no public administrative surface.
TLS everywhere in transit. Credentials and integration tokens are sealed in an envelope-encrypted vault and are never logged, never placed in URLs, and never shown back in full after entry.
Agents operate under earned autonomy: they ship in draft-only mode, and every capability that moves money, touches payroll, signs anything, or contacts the outside world is gated behind explicit human approval and rate caps. Every automated action writes an auditable record with its lineage — what ran, why, and on whose authority.
Customer data sent to model providers is used for inference only — we do not permit training on customer data. Model calls carry the minimum context the task needs.
Email [email protected] with details. We acknowledge within 2 business days, and we do not pursue good-faith researchers.
Formal certification (SOC 2) is on the roadmap as the customer base grows; the controls above are in place today. Ask us for current specifics before relying on a certification claim.