Trust

Security at AdviHR

Tenant isolation

Every record is tagged with a tenant ID, enforced at the database layer via PostgreSQL Row-Level Security in production. No cross-tenant reads or writes are possible.

Encryption everywhere

TLS 1.2+ in transit. AES-256 at rest for databases, object storage, and backups. Secrets are stored in your platform vault, never in source.

Strong authentication

JWT-based sessions, optional TOTP two-factor for admins, Google Workspace single sign-on, and (coming soon) SAML 2.0 for enterprises.

Audit logging

Every security-sensitive action — sign-in, role change, employee creation, payroll run, billing event — is logged with user, IP, and timestamp. Logs are retained for 3 years.

Data residency

Production data is hosted in the Asia-Pacific (Mumbai) region by default. Other regions available for enterprise customers.

Compliance & attestations

India DPDP Act-aligned data handling. SOC 2 Type I in progress (target: H2 next fiscal). Annual third-party penetration test.

Reporting a vulnerability

We welcome responsible disclosure from security researchers. Please emailsecurity@advihr.comwith a proof of concept and we will respond within 3 business days. We will not pursue legal action against good-faith research that respects user privacy and the public interest.