Security & trust
What the platform does to protect HR data
This page lists only controls that exist in the NanoHRMS code today. Where something is still being built, we say so.
Isolation
Your tenant’s data stays in your tenant
Row-level security in the database
Tenant tables have PostgreSQL row-level security enabled and forced, so the database itself filters every query to the current tenant — not just the application code.
Tenant-scoped relationships
Relationships between records carry the tenant in their keys, so a record cannot be linked to another tenant’s data.
Accountability
An audit trail that shows tampering
Append-only, hash-chained audit events
Each tenant’s audit events are numbered in sequence and chained with SHA-256 hashes. The database rejects updates and deletes on the audit table, and a changed entry breaks the chain.
Safe outbound webhooks
Webhook destinations are checked before delivery to block requests to internal network addresses.
Encryption
Sensitive data is encrypted by the application
Field-level encryption
Sensitive fields are encrypted with AES-256 before they are written to the database.
Per-tenant secret protection
Tenant secrets such as integration credentials are protected with AES-GCM authenticated encryption.
Privacy
Data-subject export and erasure
Export
An administrator can file an export request for a person. It runs as a background job, and the export file is encrypted with AES-256 using a key shown once to the requester.
Erasure
Erasure requests follow the same tracked process, so every request has a status and a record.
Self-service privacy requests by employees are not yet enabled; requests are filed by an administrator.
Access
Sign-in and session controls
Passkeys
Passkey-first sign-in, with secure remember-me sessions.
SSO and SCIM
OpenID Connect per tenant (SAML 2.0 on the roadmap), and SCIM user provisioning.
Tenant policy
Password rules and history, lockout after repeated failures, and session and idle timeouts.
Status
What we do not claim
NanoHRMS is in early access. We do not currently hold SOC 2, ISO 27001 or other third-party certifications, and we do not publish uptime figures yet. If you find a security issue, please email [email protected].
See NanoHRMS on your own data
NanoHRMS is in early access. Tell us how many people you pay and in which countries, and we will set up an evaluation tenant with you.