HR data is the most sensitive data a company holds. We treat it that way.
Employees see their own information, managers see their team's, and admins control the rest. Everything below is a checkable fact about the shipped product: no badges, no certifications we do not hold, and the gaps stated alongside the strengths.
Each one is a fact about the shipped product.
Where a restriction matters, it lives in a database policy or a trigger rather than in a screen, and that is what makes it sayable.
Isolation enforced by the database, not by good intentions.
Every tenant table carries your organization's ID, with row-level security enabled and forced. Cross-tenant isolation is covered by automated tests that run on every change.
Hosted in the EU.
Your application, database, file backups and error monitoring all run in EU regions (Ireland and Dublin). Every processor we use is named on our subprocessor page, including the few that operate outside the EU and the safeguards that cover them.
GDPR is a feature, not a policy page.
Per-person data export and right-to-erasure are built into the product. Erasure retains what employment law requires and tombstones the rest.
Your keys, your rules.
MFA and passkeys for everyone; SAML single sign-on and enforced sign-in domains on Enterprise. Turn on enforcement for your domain and password sign-in stops working there, so access follows your identity provider.
A real audit trail.
Admin and system actions are recorded in an append-only audit log: who did what, when, to whom.
Whistleblowing, the EU way.
An anonymous reporting channel designed for EU Directive 2019/1937: access-coded, admin-walled, and included on every plan, free included.
Data that deletes itself on a clock you set.
Set how long audit history, notifications, rejected candidates' CVs and expiry records are kept. Scheduled sweeps enforce it, so retention is a setting rather than something an admin has to remember.
Sensitive records stay narrow.
Work permits, right-to-work documents, certifications and sick notes are readable by admins and by the person they belong to. Not by their manager: immigration status and a diagnosis are not a manager's business, and the database policy is what enforces that.
Leaving is a checklist, not a memory.
An exit runs backwards from the last working day: equipment back, documents retained, and sessions revoked as an explicit step that lands in the audit log. Access ending is a recorded fact, not an intention.
A working-time record nobody can quietly edit.
For the people you clock, the daily total is derived from timestamped punches rather than typed in, and a recorded punch cannot be edited by anyone, including an admin. A correction is a separate adjustment recorded beside the original, with the measured minutes kept next to the rounded ones.
Anonymous feedback that is actually anonymous.
In 360 and upward feedback, a written answer is readable by no one but the person who wrote it. Results exist only as aggregates, released after the cycle closes and only once enough people have replied, on a threshold the cycle sets. There is no admin screen behind it.
Pay-gap numbers without a pay-gap list.
Gender is self-declared, optional, and off until you turn it on. Only the person who declared it can ever read it: there is no admin view, no manager view, and the value never reaches the audit log. Admins get the report and a count of who has answered, with any group smaller than five suppressed so a number cannot identify a person.
What a security review will find.
A summary of the full security page, which goes into the detail a reviewer needs and is kept in step with the code.
Where your data lives
Database and file storage on Supabase in AWS eu-west-1 (Ireland). Application compute on Vercel, pinned to Dublin. Off-site file backups on Cloudflare R2 under EU jurisdiction. Every vendor with access to customer data is named on the subprocessor page before it processes anything.
Tenant isolation
Row-level security is enabled and forced on every table that carries customer data, with explicit write checks and composite foreign keys, so a row cannot be written into or reference another organisation. An isolation test suite impersonates users from different organisations on every change.
Encryption
TLS on every connection with two-year HSTS. Database and files encrypted at rest by the platform. Integration credentials encrypted under our own key on top; API tokens stored only as hashes. Uploaded files are served through short-lived signed URLs, never public links.
Access control
Employee, manager and admin roles per organisation. Two-factor authentication for everyone on every plan, and admins can require it. Sensitive actions need a second factor verified in the last ten minutes. Everyone can see and revoke their own sessions. SAML single sign-on with enforced sign-in domains on Enterprise.
Our own access
Support access to tenant data requires an enrolled second factor, and suspending, exporting, re-planning or deleting an organisation needs one verified in the last ten minutes. Staff actions against your organisation land in your audit log, where your admins can see them.
Backups and recovery, stated plainly
Daily database backups and a daily archive of every storage bucket, restore-tested in August 2026 with the isolation suite re-run against the restored copy. Recovery point: up to 24 hours, because point-in-time recovery is not yet purchased. Recovery time: not yet measured, so not published.
Your rights, inside the product
Any employee can export their complete record as a machine-readable bundle; an admin can produce it for a subject access request. An admin can erase an offboarded member, scrubbing personal data in place while the employment record the employer must keep and the audit trail survive.
What we do not have
No third-party penetration test yet. No ISO 27001 certificate and no SOC 2 report: we run an information security management system built to ISO 27001:2022 and have completed an internal gap assessment, and an internal assessment is not an audit. We say this because you would find out anyway.
Questions a page can't answer?
Write to security@hexense-hr.com and a person who works on the product will reply.
Up to 10 people free · No credit card · No sales call