Trust & Security

Security at PrimeHR

Enterprise-grade security built into every layer · so your payroll, HR, and financial data is always protected.

256-bit AES · TLS 1.3 · Mumbai, India · Data never leaves India

Encryption Everywhere

AES-256 at rest, TLS 1.3 in transit. Every byte encrypted before it touches our disks.

Indian Data Residency

All data stored exclusively on secure cloud infrastructure in Mumbai, India. Never leaves India.

Zero-Trust Access

RBAC, MFA for admins, and least-privilege principles across all internal systems.

1Infrastructure & Hosting

PrimeHR is hosted entirely on secure cloud infrastructure in Mumbai, India. Our architecture is designed for resilience and isolation:

  • Network isolation · each environment runs in a dedicated private network with strict security group rules
  • Private subnets · databases not directly accessible from the public internet
  • WAF · Web Application Firewall filters SQLi, XSS, and malicious traffic
  • DDoS mitigation · Shield protection on all public endpoints
  • CDN · static assets served via global content delivery network
  • Load balancing · traffic distributed across multiple availability zones for high availability

2Data Encryption

At Rest

  • All databases encrypted with AES-256 using cloud-managed key management
  • Object storage (documents, payslips, attachments) uses server-side encryption
  • Encryption keys rotated annually; access is logged

In Transit

  • TLS 1.3 enforced on all client-server communication (TLS 1.2 minimum)
  • HSTS with max-age of one year
  • SSL/TLS certificate management with automatic renewal
  • Internal service-to-service communication is also encrypted

Sensitive Fields

Aadhaar numbers, bank account details, and PAN are additionally encrypted at the application layer before storage, with field-level keys separate from database keys.

3Access Control & Authentication

  • RBAC · granular permission sets: Super Admin, HR Manager, Finance Manager, Employee, and custom roles
  • MFA · mandatory for all administrator accounts; available for all users
  • SSO · SAML 2.0 and OAuth 2.0 (Google Workspace, Microsoft 365) for enterprise customers
  • Session management · sessions expire after 8 hours of inactivity; refresh tokens rotated on each use
  • Audit logs · all login events, data exports, and config changes logged with timestamp and IP
  • IP allowlisting · enterprise customers can restrict access to approved IP ranges

4Backups & Disaster Recovery

  • Daily backups · full database snapshots every 24 hours, retained for 30 days
  • PITR · transaction logs enable recovery to any second within a 7-day window
  • Multi-zone replication · automatic failover within 60 seconds
  • RTO: < 4 hours · RPO: < 1 hour
  • Disaster recovery drills conducted biannually

5Compliance & Certifications

PrimeHR is built to align with Indian regulations and international best practices:

DPDP Act 2023

India Digital Personal Data Protection Act

IT Act 2000

Information Technology Act & rules

Labour Law

PF, ESI, TDS, Gratuity compliance built-in

GST Ready

e-invoicing, IRN, GSTR reconciliation

ISO 27001 Aligned

Controls aligned with ISO/IEC 27001:2022

SOC 2 Roadmap

SOC 2 Type II audit in progress FY26-27

6Application Security

  • OWASP Top 10 · addressed in every development cycle and code review
  • SAST · automated security scanning on every pull request
  • Dependency scanning · third-party libraries scanned for known CVEs on every build
  • Penetration testing · annually by a CERT-In empanelled independent firm
  • CSRF protection · all state-changing endpoints require CSRF tokens
  • Rate limiting · API endpoints rate-limited to prevent brute-force and enumeration attacks
  • CSP headers · strict Content Security Policy to prevent XSS
  • SQLi prevention · parameterised queries throughout; no raw SQL from user input

7People & Processes

  • Security training · mandatory quarterly security awareness training for all engineers
  • Background checks · conducted for all employees with production access
  • Least privilege · production data access restricted to minimal group with MFA; reviewed monthly
  • Change management · all production changes require peer review, automated testing, and staged rollouts
  • Vendor management · all sub-processors undergo security review before onboarding

8Incident Response

PrimeHR maintains a documented Incident Response Plan with the following stages:

Detection & Triage (0·1 hour)

Automated alerts from AWS GuardDuty and CloudTrail trigger the on-call security engineer. Incident classified by severity (Critical / High / Medium / Low).

Containment (1·4 hours)

Affected systems isolated. Access revoked as necessary. Forensic snapshots taken before remediation.

Eradication & Recovery (4·24 hours)

Root cause identified and eliminated. Systems restored from clean backups. All potentially exposed credentials rotated.

Customer Notification (within 72 hours)

Affected customers notified within 72 hours of a confirmed breach, per applicable data-protection law, including nature of incident, data affected, and actions taken.

Post-incident Review

Blameless post-mortem within 5 business days. Findings and preventive measures documented and tracked to completion.

9Responsible Disclosure

We welcome security researchers who identify vulnerabilities. Please report responsibly · do not exploit or publicly disclose before we have addressed it.

Scope: primehr.in, app.primehr.in, and all *.primehr.in subdomains.
Out of scope: Social engineering, physical attacks, denial of service.
We commit to: Acknowledging your report within 2 business days, keeping you informed, and crediting researchers (with consent) upon resolution.

Report a Security Vulnerability

Found something? Please disclose responsibly. We take all reports seriously and resolve confirmed findings quickly.