Security
Built to protect people data
HaloHR is designed with security at every layer — from the database to the browser. Multi-tenant isolation is not an afterthought; it is the architecture.
Tenant isolation
Every client workspace is a separate tenant. Supabase Row-Level Security (RLS) ensures users see only data in their tenant.
Role-based access
Permissions are enforced at the route, component, and database levels. A user cannot escalate privileges by editing client storage.
Encrypted infrastructure
Data is encrypted in transit and at rest, and backups are encrypted. The application runs on a distributed edge network.
Audit logging
Role changes and key financial and document events are written to an append-only activity log and retained for compliance review.
Compliance controls
Track credentials, policies, evidence, and compliance tasks. Scope access by role and client assignment so only assigned staff can act.
Single sign-on
Every plan includes email/password, magic link, and OAuth sign-in with multi-factor authentication. SAML SSO and SCIM provisioning are on the roadmap, not shipped.
Data handling
You control your data
We do not train AI models on your data without explicit consent. Your documents, employee records, and conversations stay in your tenant.
- Residency and retention documented per policy, with scheduled purge jobs
- Right to export all data at any time
- DPA available on request
- No third-party ad tracking in the app
Is my data encrypted?
Yes. All data is encrypted in transit with TLS and at rest using AES-256.
Can consultants access all clients?
No. Access is scoped to explicit client assignments.
Are AI conversations stored?
Only if needed for feature operation. You can request deletion.
Have a security question?
Our team can walk you through architecture, answer questionnaires, and provide a DPA or security whitepaper.