Where People and Business Grow TogetherStart your 30-day free trial
Enterprise-grade trust, by design

Protect employee data with deliberate controls and transparent assurance status.

duoHR brings cloud hosting, encryption, role-based access, audit logs, regular backups and controlled workflows into the product trust model.

No generic sales tour Built around your workflows
Trust across the service boundary
PeopleProcessApplicationInfrastructure
SOC 2 certification

In progress, according to the supplied duoHR sales material.

Current status
GDPR alignment

Underway, according to the supplied duoHR sales material.

Current status
Assurance transparency

“In progress” and “underway” are not certifications. Final public claims, reports, hosting locations, subprocessors, data residency, uptime commitments and control evidence must be validated before production launch.

Security foundation

Controls across the complete service boundary.

The production security programme should be maintained jointly by Product, Engineering, Security, Legal and Operations.

Cloud-hosted service

A cloud delivery model designed to support controlled access, managed updates and scalable operations.

Encrypted data

Encryption controls should protect data in transit and at rest, with secure secrets and key-handling practices.

Role-based access

Permissions align employee, manager, HR, payroll, Finance and administrative access with responsibility.

Audit logs

Sensitive changes, approvals, administrative actions and configured workflows require traceable history.

Regular backups

Backup schedules, restoration testing and recovery responsibilities support service resilience.

Compliance-ready controls

Configuration, evidence and operating procedures can support customer compliance programmes without replacing legal advice.

Access by responsibility

People should see only the data and actions required for their role.

Design access around employees, managers, HR operations, payroll processors, Finance reviewers, IT administrators and auditors. Sensitive fields, bulk exports, impersonation and configuration actions require particular attention.

Role-based access Sensitive-field controls Approval separation Export governance
Illustrative access model
Employee

Own profile, documents and requests

Manager

Permitted team data and actions

HR operations

Lifecycle and policy workflows

Payroll

Pay data and payroll processing

Leadership

Approved aggregated workforce insight

Privacy and responsible AI

Configuration and governance determine how policy becomes practice.

Define notices, purpose, access, retention, exports, correction paths, human review, prohibited AI uses, deletion or archival handling and vendor responsibility around actual employee-data flows.

Documents customers may request

  • Security overview and architecture
  • Data-processing agreement
  • Subprocessor list
  • Incident and continuity process
  • Backup and recovery approach
  • Access-control matrix
  • Responsible-AI control summary
Review DPA framework
Security review

Include IT, Legal and Security early in evaluation.

Map data flows, roles, integrations, hosting assumptions, AI use cases and assurance evidence required for procurement.