Skip to main content
BizzFieldHRMS

SECURITY

Access Scoped Server-Side, Not Decided By The Client.

Role-based access control enforced from the org hierarchy, role-scoped document storage, and OTP-verified account security — the client is never trusted with scope.

3Security Modules

HOW ACCESS IS ENFORCED

Security That Doesn't Depend On The Client

Filtering data in the frontend isn't access control, it's UI decoration. Real scoping happens on the server, on every request.

Role-Based Access Control

Access is enforced server-side from the org hierarchy — the client is never trusted with scope.

Scope From The Hierarchy You Already Have

A manager's scope is their subtree, an employee's scope is themselves, and admins see everything — no separate permission table to keep in sync.

Role-Scoped Document Storage

Secure, S3-backed document storage with role-scoped visibility down to individual document categories.

Email-OTP-Verified Password Changes

Password changes require email OTP verification, backed by a full, auditable permissions matrix.

Every Approval Leaves An Audit Trail

Pay run approvals, declaration reviews and record changes are recorded with who acted and when.

Built With India's DPDPA In Mind

Data handling practices are designed around the principles of India's Digital Personal Data Protection Act.

ACCESS AUDIT SNAPSHOT

Access Control, In Action

A sample view of server-side access scoping on a running BizzField HRMS account — illustrative data.

Documents Role-Scoped
3,214
100% S3-backed
OTP-Verified Password Changes
22
This month
DPDPA-Aligned Consent Logs
100%
Complete logging
Permission Matrix Entries
38
Role × Module

Access Requests By Outcome

Allowed (Scoped)4,666
Blocked (Out Of Scope)146
Flagged For Review48

Recent Security Events

Document access request — HR only, granted2:40 PM
Password reset — OTP verified1:15 PM

COMPLIANCE & CERTIFICATIONS

Industry Standards & Compliance Frameworks

We're aligning our infrastructure with global security frameworks so your employee records stay safe and compliant — we'd rather tell you a certification is in progress than claim one we don't hold yet.

SOC 2 Type II — Audit In Progress

Our infrastructure and operational processes are being prepared for an independent annual SOC 2 Type II audit to verify security controls; we'll confirm once it's complete.

ISO 27001 — Certification In Progress

Our information security management system (ISMS) is being built toward ISO 27001 certification to safeguard confidentiality, integrity, and availability; we'll confirm once it's issued.

India DPDPA & GDPR

Engineered around strict privacy mandates, including complete consent logging, user data export, and deletion rights.

INFRASTRUCTURE & DATA PRIVACY

Bank-Grade Encryption & Resilient Infrastructure

Data privacy is protected with industry-standard encryption, strict access isolation, and continuous monitoring.

AES-256 Storage Encryption

All client employee databases, bank records, and document files are encrypted at rest with AES-256 keys.

TLS 1.3 Transmission Security

All browser connections and data-in-transit transactions are secured using modern TLS 1.3 encryption protocols.

Continuous Automated Backups

Daily automated database snapshots are stored in isolated geographic locations to ensure immediate recovery.

Vulnerability Scanning

Continuous automated scanning and bi-annual third-party penetration testing detect bugs proactively.

FAQ

Security — Questions We Get Asked

Server-side, on every request, from the org hierarchy — a manager's scope is their subtree, an employee's scope is themselves, and admins see everything. It isn't a frontend toggle that hides a column; the server never returns data outside a caller's scope in the first place.

Documents are stored in S3-backed storage with role-scoped visibility down to individual document categories, so sensitive records stay visible only to the roles that need them.

Password changes require email OTP verification, and every account action is checked against a full, auditable permissions matrix.

Data handling practices are designed around the principles of India's Digital Personal Data Protection Act (DPDPA).

See BizzField HRMS Security, Not Just Read About It

Walk through how role scoping, document visibility and audit trails work on your own org structure.