Security & data protection

Your people data,
handled with care.

What SincHR does to protect employee and pay data, stated plainly — and who to contact when you need more than a web page.

Access

Who sees what, enforced on the server.

Pay data is the most sensitive thing an HR platform holds. Access to it is decided by role and checked on every request, not only hidden in a menu.

🔐
Role-based access
Owners, HR, managers and employees each see only what their role allows. Reporting and pay-parity views are limited to owners and HR, and feature access is enforced by the API as well as the interface.
🫥
Field-level masking for managers
Managers see the people they manage, with sensitive fields masked. Pay information stays with HR and owners unless a workflow deliberately shares it — for example an employee's own pay-information request.
🧾
Audit trail
Changes to employee master data and pay bands are recorded with who made them and when, so a pay decision can be evidenced months later rather than reconstructed.
🍪
Secure sessions
Sessions use HTTPS-only cookies in production and every state-changing request carries a CSRF token. The application refuses to start in production with a weak or default secret key.
GDPR

Data protection, in writing.

The documents and contacts a data-protection review asks for.

What we do not claim SincHR does not currently hold a SOC 2 report or ISO 27001 certification, and we would rather say so than put a badge on this page. If a certification is a condition of your purchase, ask us where we are on that roadmap.
Responsible disclosure

Found something? Tell us.

Email security@sinchr.com with what you found and how to reproduce it. We read every report, reply to the reporter, and do not take action against good-faith research.

Need the details?

Ask a security question,
get an answer from a person.

Request the DPA, send us your vendor questionnaire, or start a trial and see how access control works with your own data.

Contact us Start your free trial No charge today