India-first HRMS · Built by ImpacteersExplore the ecosystem
Security and trust

Protect employee data with deliberate product controls—and verify every assurance claim.

duoHR describes tenant isolation, role and data scopes, operational audit, security events, sensitive-data access records and governed AI. Certification, hosting, uptime and recovery evidence must be confirmed before publication or contract.

No generic sales tour Built around your workflows
Trust across the service boundary
TenantIdentityApplicationData
No unverified certification claims

The consolidated product material explicitly says not to claim ISO certification, SOC 2 certification, uptime SLA or disaster-recovery guarantees without separate evidence. This site therefore describes product controls and requests current assurance documents during evaluation.

Product control model

Security operates through identity, scope, history and review.

The production programme still requires current evidence from Product, Engineering, Security, Legal and Operations.

Tenant-aware access

Tenant identity is described as coming from the signed request context rather than user-supplied headers or form data.

Role and data scope

System and custom roles can limit modules, actions and organisational scope across self, team, department, business unit or wider access.

Operational audit

Important employee, policy, payroll and workflow changes retain a traceable history.

Security events

Authentication and security events are separated from ordinary operating history for focused review.

Sensitive-data access

Access to sensitive employee data can be tracked separately from ordinary transactions.

Governed AI

AI actions are bounded by tenant, role, current screen, approved action catalog and mandatory human confirmation.

Access by responsibility

People should see only the data and actions required for their role.

Design access around employees, managers, HR operations, payroll, Finance, administrators and auditors. Sensitive fields, exports, impersonation and configuration require particular attention.

Role-based access Organisational data scope Sensitive-access records Approval separation
Illustrative access model
Employee

Own permitted profile, documents and requests

Manager

Permitted reporting-team data and actions

HR operations

Lifecycle, policy and service workflows

Payroll

Pay data and payroll processing

Leadership

Approved aggregated workforce insight

Security due diligence

Ask for evidence that matches the service actually being purchased.

Confirm hosting location, encryption, backup and restore testing, incident response, subprocessors, authentication controls, logging, retention, RPO/RTO, vulnerability management and AI data flow.

Documents customers may request

  • Architecture and data-flow overview
  • Data-processing agreement
  • Subprocessor list
  • Access-control matrix
  • Backup and recovery evidence
  • Incident response process
  • Responsible-AI control summary
Review DPA framework
Security review

Include IT, Legal and Security early in evaluation.

Map data flows, roles, hosting assumptions, integrations, AI use cases and the exact evidence required for procurement.