HRMS SECURITY
Access Scoped Server-Side, Not Decided By The Client.
Employee records are only as safe as the rules on who can open them. Access is scoped on the server from the org hierarchy, documents are restricted by role, and password changes are confirmed by email OTP.
HOW ACCESS IS ENFORCED
Security That Doesn't Depend On The Client
Filtering data in the frontend isn't access control, it's UI decoration. Real scoping happens on the server, on every request.
Role-Based Access Control
Every request is checked on the server against the org hierarchy, so out-of-scope data never reaches the browser.
Scope From The Hierarchy You Already Have
A manager's scope is their subtree, an employee's scope is themselves, and admins see everything — no separate permission table to keep in sync when reporting lines change.
Role-Scoped Document Storage
Employee documents sit in S3-backed storage, and each document category is visible only to the roles that need it.
Email-OTP-Verified Password Changes
Password changes need an email OTP before they take effect, backed by a full, auditable permissions matrix for each role.
Every Approval Leaves An Audit Trail
Pay run approvals, declaration reviews and record changes are recorded with who acted and when.
Built With India's DPDPA In Mind
Data handling practices are designed around the principles of India's DPDPA — a design approach, not a certification.
ACCESS AUDIT SNAPSHOT
Access Control, In Action
A sample view of server-side access scoping on a running BizzField HRMS account — illustrative data, not customer results.
Access Requests By Outcome
Recent Security Events
COMPLIANCE & CERTIFICATIONS
Certification Status And Privacy Frameworks
Neither SOC 2 Type II nor ISO 27001 is held today; both are in progress. We would rather tell you a certification is underway than claim one we do not hold yet.
SOC 2 Type II — Audit In Progress
Our infrastructure and operational processes are being prepared for an independent SOC 2 Type II audit of security controls; we'll confirm once it's complete.
ISO 27001 — Certification In Progress
Our information security management system (ISMS) is being built toward ISO 27001 certification; we'll confirm once it's issued.
India DPDPA & GDPR Principles
Data handling is designed around the principles of India's DPDPA and the GDPR, including consent logging, user data export, and deletion rights.
INFRASTRUCTURE & DATA PRIVACY
Encryption, Backups And Security Testing
How employee, bank and document data is protected at rest and in transit, backed up, and tested for vulnerabilities.
AES-256 Storage Encryption
Employee records, bank details, and document files are encrypted at rest with AES-256.
TLS 1.3 Transmission Security
Browser connections and other data in transit are secured with TLS 1.3 encryption.
Daily Automated Backups
Daily automated database snapshots are stored in isolated geographic locations to support recovery.
Vulnerability Scanning
Continuous automated scanning and bi-annual third-party penetration testing help find vulnerabilities early.
FAQ
Security — Questions We Get Asked
Server-side, on every request, from the org hierarchy — a manager's scope is their subtree, an employee's scope is themselves, and admins see everything. It isn't a frontend toggle that hides a column; the server never returns data outside a caller's scope in the first place.
Access follows the org hierarchy, so when a reporting line changes, the person's scope and their managers' views change with it, without a separate access request or a permission table to update.
Documents are stored in S3-backed storage with role-scoped visibility down to individual document categories, so sensitive records stay visible only to the roles that need them.
A password change is confirmed by an email OTP before it takes effect. Account actions are checked against a full, auditable permissions matrix that defines what each role can view and do.
Yes. Pay run approvals, declaration reviews and record changes are recorded with who acted and when, so finance and security teams can review who did what.
Data handling practices are designed around the principles of India's Digital Personal Data Protection Act (DPDPA). That describes how data is handled; it is not a certification.
Not yet. A SOC 2 Type II audit and ISO 27001 certification are both in progress, and neither is held today. This page will say so when either is complete.
See BizzField HRMS Security, Not Just Read About It
Walk through how role scoping, document visibility and audit trails work on your own org structure.

