Encryption Everywhere
AES-256 at rest, TLS 1.3 in transit. Every byte encrypted before it touches our disks.
Indian Data Residency
All data stored exclusively on secure cloud infrastructure in Mumbai, India. Never leaves India.
Zero-Trust Access
RBAC, MFA for admins, and least-privilege principles across all internal systems.
1Infrastructure & Hosting
PrimeHR is hosted entirely on secure cloud infrastructure in Mumbai, India. Our architecture is designed for resilience and isolation:
- Network isolation · each environment runs in a dedicated private network with strict security group rules
- Private subnets · databases not directly accessible from the public internet
- WAF · Web Application Firewall filters SQLi, XSS, and malicious traffic
- DDoS mitigation · Shield protection on all public endpoints
- CDN · static assets served via global content delivery network
- Load balancing · traffic distributed across multiple availability zones for high availability
2Data Encryption
At Rest
- All databases encrypted with AES-256 using cloud-managed key management
- Object storage (documents, payslips, attachments) uses server-side encryption
- Encryption keys rotated annually; access is logged
In Transit
- TLS 1.3 enforced on all client-server communication (TLS 1.2 minimum)
- HSTS with max-age of one year
- SSL/TLS certificate management with automatic renewal
- Internal service-to-service communication is also encrypted
Sensitive Fields
Aadhaar numbers, bank account details, and PAN are additionally encrypted at the application layer before storage, with field-level keys separate from database keys.
3Access Control & Authentication
- RBAC · granular permission sets: Super Admin, HR Manager, Finance Manager, Employee, and custom roles
- MFA · mandatory for all administrator accounts; available for all users
- SSO · SAML 2.0 and OAuth 2.0 (Google Workspace, Microsoft 365) for enterprise customers
- Session management · sessions expire after 8 hours of inactivity; refresh tokens rotated on each use
- Audit logs · all login events, data exports, and config changes logged with timestamp and IP
- IP allowlisting · enterprise customers can restrict access to approved IP ranges
4Backups & Disaster Recovery
- Daily backups · full database snapshots every 24 hours, retained for 30 days
- PITR · transaction logs enable recovery to any second within a 7-day window
- Multi-zone replication · automatic failover within 60 seconds
- RTO: < 4 hours · RPO: < 1 hour
- Disaster recovery drills conducted biannually
5Compliance & Certifications
PrimeHR is built to align with Indian regulations and international best practices:
DPDP Act 2023
India Digital Personal Data Protection Act
IT Act 2000
Information Technology Act & rules
Labour Law
PF, ESI, TDS, Gratuity compliance built-in
GST Ready
e-invoicing, IRN, GSTR reconciliation
ISO 27001 Aligned
Controls aligned with ISO/IEC 27001:2022
SOC 2 Roadmap
SOC 2 Type II audit in progress FY26-27
6Application Security
- OWASP Top 10 · addressed in every development cycle and code review
- SAST · automated security scanning on every pull request
- Dependency scanning · third-party libraries scanned for known CVEs on every build
- Penetration testing · annually by a CERT-In empanelled independent firm
- CSRF protection · all state-changing endpoints require CSRF tokens
- Rate limiting · API endpoints rate-limited to prevent brute-force and enumeration attacks
- CSP headers · strict Content Security Policy to prevent XSS
- SQLi prevention · parameterised queries throughout; no raw SQL from user input
7People & Processes
- Security training · mandatory quarterly security awareness training for all engineers
- Background checks · conducted for all employees with production access
- Least privilege · production data access restricted to minimal group with MFA; reviewed monthly
- Change management · all production changes require peer review, automated testing, and staged rollouts
- Vendor management · all sub-processors undergo security review before onboarding
8Incident Response
PrimeHR maintains a documented Incident Response Plan with the following stages:
Detection & Triage (0·1 hour)
Automated alerts from AWS GuardDuty and CloudTrail trigger the on-call security engineer. Incident classified by severity (Critical / High / Medium / Low).
Containment (1·4 hours)
Affected systems isolated. Access revoked as necessary. Forensic snapshots taken before remediation.
Eradication & Recovery (4·24 hours)
Root cause identified and eliminated. Systems restored from clean backups. All potentially exposed credentials rotated.
Customer Notification (within 72 hours)
Affected customers notified within 72 hours of a confirmed breach, per applicable data-protection law, including nature of incident, data affected, and actions taken.
Post-incident Review
Blameless post-mortem within 5 business days. Findings and preventive measures documented and tracked to completion.
9Responsible Disclosure
We welcome security researchers who identify vulnerabilities. Please report responsibly · do not exploit or publicly disclose before we have addressed it.
Out of scope: Social engineering, physical attacks, denial of service.
We commit to: Acknowledging your report within 2 business days, keeping you informed, and crediting researchers (with consent) upon resolution.
Report a Security Vulnerability
Found something? Please disclose responsibly. We take all reports seriously and resolve confirmed findings quickly.