Security

Your payroll data is sensitive.
We treat it that way.

Salary data, national ID numbers, KRA PINs — this is some of the most sensitive data a business holds. Here is how we protect it.

Encryption at rest and in transit

All data is encrypted with AES-256 at rest. All communications use TLS 1.3. Encryption keys are managed separately from data and rotated quarterly.

Data residency in East Africa

Your data never leaves East Africa. Infrastructure is hosted in the region to comply with Kenya's data localisation requirements and reduce latency.

Schema-level tenant isolation

Each customer's data lives in a separate database schema. There is no shared table between tenants. A query from one account cannot reach another account's data.

Full audit logging

Every data access, change, and API call is logged with timestamp, user identity, and IP address. Audit logs are immutable and retained for 7 years.

Role-based access control

Platform access is governed by roles with the principle of least privilege. HR Managers, Payroll Officers, Line Managers, and Employees each see only what their role permits.

Penetration testing

We conduct third-party penetration tests at least annually. Critical findings are resolved before the next payroll cycle. Reports are available to enterprise customers under NDA.

Certifications & compliance

KDPA registeredYes
GDPR-aligned data handlingYes
Encryption at restAES-256
Encryption in transitTLS 1.3
SOC 2 Type 1In audit
ISO 27001In roadmap
Audit log retention7 years
Breach notification SLA72 hours