Last updated: [EFFECTIVE DATE]
Security and Data Protection
A cautious overview of security practices reflected in the current product implementation.
This draft is provided for legal review and is not legal advice. Replace bracketed text and confirm the document for the jurisdictions and service configuration that apply before publication.
Controls reflected in the implementation
HutchHR is designed with authenticated access, role-based permissions, tenant-scoped backend authorization, password hashing, audit logging for selected actions, and private object storage for employee documents and leave attachments. Payroll bank account numbers are encrypted by the application before storage. The frontend is not an authorization boundary; the backend is intended to enforce access decisions.
Operations and reporting
We use service providers to support infrastructure, storage, and email delivery as listed on the Subprocessors page. Report a suspected security issue to [SECURITY REPORTING EMAIL]. Do not send sensitive information in an initial report. We will assess reports and respond according to [INCIDENT RESPONSE PROCESS PLACEHOLDER].
Items requiring security review
TODO FOR LEGAL/SECURITY REVIEW: verify transport encryption configuration, encryption at rest for each system, key management, backups and restoration testing, vulnerability-management process, secure-development lifecycle, employee-access reviews, hosting locations, incident-response timelines, and formal certifications. This page makes no assurance of absolute security or unverified compliance certification.
Questions about these draft documents? Contact [CONTACT EMAIL].