Zaffre HRM
Security

Built for organizations that take security seriously.

Enterprise-grade controls across every layer — from network and storage to employee-level access and monitoring.

Encryption in transit

SSL / TLS on every connection. No plain-HTTP endpoints in production.

Encryption at rest

Passwords, payroll data, and sensitive PII encrypted with industry-standard algorithms.

Role-based access control

Granular RBAC — every action checked against a role + scope policy.

Device / IP / location locks

Restrict access by IP range, geographic location, or trusted device ID.

Audit logs

Every sensitive action — payroll runs, settlements, role changes — logged with actor and timestamp.

Monitoring transparency

Remote monitoring is disclosed to employees; admins control what is captured.

Multi-tenant isolation

Each company's data is logically isolated. No cross-tenant access paths.

Backup & recovery

Automated backups with point-in-time recovery. RPO measured in minutes.

Vendor processors

Sub-processors documented and reviewed for compliance with data protection laws.

Data ownership

Your employer is the data controller — always.

Employees' personal data remains under the control of the employer. Zaffre Tech acts as a data processor. All access, export, or deletion requests are routed through your employer's HR or system administrator. See our Privacy Policy for full details.

Security questions? Send them our way.

We respond to vendor security questionnaires for enterprise procurement.