Skip to content
PulseHR

Our approach to security

Employee data includes identity, salary and health information. Below we explain in plain language how the platform protects it.

Companies are kept apart

Every record on the platform belongs to one company. Each query is automatically limited to your company's data. A user from one company cannot reach another company's data by changing a number in the address bar or in a request.

The same protection, a second time, in the database

Company separation is not left to application code alone; the database itself independently enforces the same separation with row-level security rules. Even if the application had a bug, the database would not return another company's data.

Everyone sees only what they need

Managers see only their own team. Sensitive areas such as people records, pay and analytics are open by default only to the authorized HR role. Multi-factor authentication (MFA) is supported.

Every feature passes unauthorized-access testing

A feature is not considered finished until we have tested whether a user of another company or role can reach its data.

Your data stays in Europe

The database and application servers are hosted in the Frankfurt region.

No biometric data

Biometric data such as fingerprints and face recognition is neither collected nor stored. The device's own fingerprint/PIN can lock the mobile app; neither the app nor the server ever sees that data.

Encrypted connection (SSL/TLS)

All connections to our site and app are encrypted with TLS (https). This is connection encryption, not a company certificate; it prevents data from being read in transit.

Designed to align with KVKK

There is no official "KVKK certificate", so we do not claim to be "certified". The platform is designed around concrete principles: managing privacy notices inside the system, deletion/anonymization when retention periods end, role-based least-privilege access, and no biometric data collection. Your company's own obligations, such as VERBİS and privacy notices, remain with your company.

Tracker-free, lightweight site

This site uses no advertising or tracking cookies; details are in the Cookie Policy.

Records and traceability

Security-related events are logged. Retention periods and post-employment deletion/anonymization rules are managed inside the system.

This page describes the platform's design principles. We do not yet hold an independent security certification; we will state it here once we have a real one.

Request a demo