In progress, according to the supplied duoHR sales material.
Protect employee data with deliberate controls and transparent assurance status.
duoHR brings cloud hosting, encryption, role-based access, audit logs, regular backups and controlled workflows into the product trust model.
Underway, according to the supplied duoHR sales material.
“In progress” and “underway” are not certifications. Final public claims, reports, hosting locations, subprocessors, data residency, uptime commitments and control evidence must be validated before production launch.
Controls across the complete service boundary.
The production security programme should be maintained jointly by Product, Engineering, Security, Legal and Operations.
Cloud-hosted service
A cloud delivery model designed to support controlled access, managed updates and scalable operations.
Encrypted data
Encryption controls should protect data in transit and at rest, with secure secrets and key-handling practices.
Role-based access
Permissions align employee, manager, HR, payroll, Finance and administrative access with responsibility.
Audit logs
Sensitive changes, approvals, administrative actions and configured workflows require traceable history.
Regular backups
Backup schedules, restoration testing and recovery responsibilities support service resilience.
Compliance-ready controls
Configuration, evidence and operating procedures can support customer compliance programmes without replacing legal advice.
People should see only the data and actions required for their role.
Design access around employees, managers, HR operations, payroll processors, Finance reviewers, IT administrators and auditors. Sensitive fields, bulk exports, impersonation and configuration actions require particular attention.
Own profile, documents and requests
Permitted team data and actions
Lifecycle and policy workflows
Pay data and payroll processing
Approved aggregated workforce insight
Configuration and governance determine how policy becomes practice.
Define notices, purpose, access, retention, exports, correction paths, human review, prohibited AI uses, deletion or archival handling and vendor responsibility around actual employee-data flows.
Documents customers may request
- Security overview and architecture
- Data-processing agreement
- Subprocessor list
- Incident and continuity process
- Backup and recovery approach
- Access-control matrix
- Responsible-AI control summary
Include IT, Legal and Security early in evaluation.
Map data flows, roles, integrations, hosting assumptions, AI use cases and assurance evidence required for procurement.