Encryption at Rest
All documents and sensitive data are encrypted using AES-256 encryption, the same standard used by banks and government agencies.
Your data security and privacy are our top priorities
All documents and sensitive data are encrypted using AES-256 encryption, the same standard used by banks and government agencies.
All data transmitted between your browser and our servers is protected by TLS 1.3 encryption over HTTPS connections.
Four distinct user roles (Owner, Admin, HR Staff, Auditor) ensure team members only see information relevant to their responsibilities.
Comprehensive logging of all actions, including who accessed what data and when. Audit logs are immutable and retained according to your plan.
Your data is stored in secure, UK-based data centers that comply with GDPR and UK data protection regulations.
We conduct regular security assessments, penetration testing, and vulnerability scans to identify and address potential risks.
We only collect and store data necessary for providing our service. You control what employee information you add to the system.
Your data is used solely for providing HR and compliance record-keeping services. We never sell or share your data with third parties for marketing purposes.
Our Privacy Policy clearly explains what data we collect, how we use it, and your rights. We notify you of any material changes.
You can export your data at any time and request deletion of your account. We provide tools to help you comply with data subject access requests.
Audit entries are immutable and cannot be altered or deleted, creating a trustworthy record of access and changes.
Every uploaded document is hashed and versioned, so evidence integrity can be verified during audits.
External auditors can be invited as read-only users with all access logged, ensuring safe, transparent reviews.
Full compliance with EU General Data Protection Regulation and UK GDPR requirements.
Information security management practices aligned with ISO 27001 standards.
Compliance with UK Data Protection Act 2018 requirements for processing personal data.
All document access uses time-limited signed URLs that expire after a short period, preventing unauthorized access even if a URL is intercepted.
Your data is backed up daily to geographically distributed locations. Backups are encrypted and tested regularly to ensure data can be restored if needed.
We maintain a comprehensive incident response plan and will notify affected users within 72 hours of discovering any data breach, as required by GDPR.
All SponsorSafe HR team members undergo regular security and privacy training. Access to production systems is strictly controlled and logged.