SECURITY
Access Scoped Server-Side, Not Decided By The Client.
Role-based access control enforced from the org hierarchy, role-scoped document storage, and OTP-verified account security — the client is never trusted with scope.
HOW ACCESS IS ENFORCED
Security That Doesn't Depend On The Client
Filtering data in the frontend isn't access control, it's UI decoration. Real scoping happens on the server, on every request.
Role-Based Access Control
Access is enforced server-side from the org hierarchy — the client is never trusted with scope.
Scope From The Hierarchy You Already Have
A manager's scope is their subtree, an employee's scope is themselves, and admins see everything — no separate permission table to keep in sync.
Role-Scoped Document Storage
Secure, S3-backed document storage with role-scoped visibility down to individual document categories.
Email-OTP-Verified Password Changes
Password changes require email OTP verification, backed by a full, auditable permissions matrix.
Every Approval Leaves An Audit Trail
Pay run approvals, declaration reviews and record changes are recorded with who acted and when.
Built With India's DPDPA In Mind
Data handling practices are designed around the principles of India's Digital Personal Data Protection Act.
ACCESS AUDIT SNAPSHOT
Access Control, In Action
A sample view of server-side access scoping on a running BizzField HRMS account — illustrative data.
Access Requests By Outcome
Recent Security Events
COMPLIANCE & CERTIFICATIONS
Industry Standards & Compliance Frameworks
We're aligning our infrastructure with global security frameworks so your employee records stay safe and compliant — we'd rather tell you a certification is in progress than claim one we don't hold yet.
SOC 2 Type II — Audit In Progress
Our infrastructure and operational processes are being prepared for an independent annual SOC 2 Type II audit to verify security controls; we'll confirm once it's complete.
ISO 27001 — Certification In Progress
Our information security management system (ISMS) is being built toward ISO 27001 certification to safeguard confidentiality, integrity, and availability; we'll confirm once it's issued.
India DPDPA & GDPR
Engineered around strict privacy mandates, including complete consent logging, user data export, and deletion rights.
INFRASTRUCTURE & DATA PRIVACY
Bank-Grade Encryption & Resilient Infrastructure
Data privacy is protected with industry-standard encryption, strict access isolation, and continuous monitoring.
AES-256 Storage Encryption
All client employee databases, bank records, and document files are encrypted at rest with AES-256 keys.
TLS 1.3 Transmission Security
All browser connections and data-in-transit transactions are secured using modern TLS 1.3 encryption protocols.
Continuous Automated Backups
Daily automated database snapshots are stored in isolated geographic locations to ensure immediate recovery.
Vulnerability Scanning
Continuous automated scanning and bi-annual third-party penetration testing detect bugs proactively.
FAQ
Security — Questions We Get Asked
Server-side, on every request, from the org hierarchy — a manager's scope is their subtree, an employee's scope is themselves, and admins see everything. It isn't a frontend toggle that hides a column; the server never returns data outside a caller's scope in the first place.
Documents are stored in S3-backed storage with role-scoped visibility down to individual document categories, so sensitive records stay visible only to the roles that need them.
Password changes require email OTP verification, and every account action is checked against a full, auditable permissions matrix.
Data handling practices are designed around the principles of India's Digital Personal Data Protection Act (DPDPA).
See BizzField HRMS Security, Not Just Read About It
Walk through how role scoping, document visibility and audit trails work on your own org structure.

