Security & compliance

Security is in the architecture, not bolted on

Isolation, encryption, least-privilege access and a provable audit trail are properties of how the system is built — the same controls whether you run SaaS or fully on-premise.

Controls

Defense in depth, by design

Every layer assumes the others can fail — identity, authorization, isolation, encryption and audit each stand on their own.

Identity & SSO

RS256 JWT access tokens with rotating, reuse-detecting refresh tokens; replay revokes the whole token family.

Capability RBAC + ABAC

A capability matrix with default-deny enforcement — every action carries one explicit decision, scoped by tenant, branch and manager-chain.

Tenant isolation

Database-per-tenant, with membership re-verified every request and a data context that fails closed when no tenant resolves.

Encryption & key control

Field-level PII encryption with customer-managed keys — envelope-encrypted, revocable, and yours to hold on-prem.

Immutable audit trail

An append-only history records who — or which agent — did what, when, and what changed, across the whole estate.

Secure SDLC

Built against the OWASP Top 10 with CI-enforced module boundaries, so security properties don't erode as the system grows.

Trust & compliance

Standards we build against

Security and compliance are part of the architecture, not an afterthought.

ISO/IEC 27001:2022SOC 2 (Trust Services Criteria)OWASP Top 10Database-per-tenant isolationCustomer-managed encryption keysImmutable audit trail

Frequently asked questions

Are you certified to ISO 27001 or SOC 2?

We engineer against ISO/IEC 27001:2022 and the SOC 2 Trust Services Criteria and can share our current posture and roadmap under NDA. Talk to us for the latest attestation status for your procurement.

How is personal data protected?

PII is encrypted at the field level with customer-managed keys and envelope encryption. On BYO-DB and on-prem you hold the key, so you can revoke access unilaterally.

Can we run a penetration test?

Yes. We support customer and third-party security testing of your environment under a coordinated scope — reach out to arrange it.

Get started

Run payroll and HR for your whole group — on one governed platform.

Book a demo and see HRMSTONE run multi-country payroll, statutory filing and approvals — as SaaS, or on-premise for banks and government.

  • Statutory-accurate, MENA & GCC
  • SaaS or on-prem, your keys
  • Arabic & English, Hijri & RTL