Skip to content
NanoHRMS

Security & trust

What the platform does to protect HR data

This page lists only controls that exist in the NanoHRMS code today. Where something is still being built, we say so.

Isolation

Your tenant's data stays in your tenant

  • Row-level security in the database

    Tenant tables have PostgreSQL row-level security enabled and forced, so the database itself filters every query to the current tenant — not just the application code.

  • Tenant-scoped relationships

    Relationships between records carry the tenant in their keys, so a record cannot be linked to another tenant's data.

Accountability

An audit trail that shows tampering

  • Append-only, hash-chained audit events

    Each tenant's audit events are numbered in sequence and chained with SHA-256 hashes. The database rejects updates and deletes on the audit table, and a changed entry breaks the chain.

  • Safe outbound webhooks

    Webhook destinations are checked before delivery to block requests to internal network addresses.

Encryption

Sensitive data is encrypted by the application

  • Field-level encryption

    Sensitive fields are encrypted with AES-256 before they are written to the database.

  • Per-tenant secret protection

    Tenant secrets such as integration credentials are protected with AES-GCM authenticated encryption.

Privacy

Data-subject export and erasure

  • Export

    An administrator can file an export request for a person. It runs as a background job, and the export file is encrypted with AES-256 using a key shown once to the requester.

  • Erasure

    Erasure requests follow the same tracked process, so every request has a status and a record.

Self-service privacy requests by employees are not yet enabled; requests are filed by an administrator.

Access

Sign-in and session controls

  • Passkeys

    Passkey-first sign-in, with secure remember-me sessions.

  • SSO and SCIM

    OpenID Connect per tenant (SAML 2.0 on the roadmap), and SCIM user provisioning.

  • Tenant policy

    Password rules and history, lockout after repeated failures, and session and idle timeouts.

Status

What we do not claim

NanoHRMS is in early access. We do not currently hold SOC 2, ISO 27001 or other third-party certifications, and we do not publish uptime figures yet. If you find a security issue, please email [email protected].

See NanoHRMS on your own data

NanoHRMS is in early access. Tell us how many people you pay and in which countries, and we will set up an evaluation tenant with you.