Transport encryption
HTTPS with TLS on every connection, including desktop tracker uploads. HTTP requests are redirected rather than served.
Attendance records, work reports and screenshots are employee personal data. This page sets out how that data is protected, who can reach it, what we do not claim, and exactly which responsibilities move to you when you self-host.
Worth putting first, because it is the paragraph most vendor security pages leave out.
Employee Desk does not hold ISO 27001 or SOC 2 certification today. If your procurement process requires a certified platform, the honest options are: run the application on your own certified infrastructure, which is precisely why the self-hosted licence exists; or wait until we hold the certification, and we will publish it here when we do rather than implying it beforehand.
HTTPS with TLS on every connection, including desktop tracker uploads. HTTP requests are redirected rather than served.
Password hashing with a modern algorithm, configurable password policy, session expiry and forced re-authentication for sensitive actions. SAML 2.0, OIDC and AD/LDAP directory sync where you need directory integration.
Employee, manager, HR and admin roles with distinct capabilities. A manager sees their own reports, not the whole company.
Who viewed what, and when — including which manager opened whose screenshot gallery. This is the control most monitoring products are missing.
Uploads are type-checked and stored outside the web root. Screenshots are served through authorised requests rather than from a guessable public URL.
Tenant scoping on every query on the shared cloud, and dedicated infrastructure on private cloud.
| Control | Cloud | Private cloud | Self-hosted |
|---|---|---|---|
| Host patching | Us | Us | You |
| Application updates | Us | Us | You, from published images |
| Encryption in transit | Us | Us | You supply the certificate |
| Encryption at rest | Us | Us | Your disk and host configuration |
| Backups | Us, daily | Us, isolated per instance | You, documented procedure |
| Access control inside the app | Product feature | Product feature | Product feature |
| Network exposure | Us | Us | You — 443 inbound only |
| Vendor access to your data | Support and incident response, logged | Same | None |
| Sub-processor in your privacy notice | Us | Us | None |
Employee attendance, activity and screenshot data is personal data. Under the Digital Personal Data Protection Act framework, the employer processing it is the entity with obligations to its employees, and the four that matter operationally are notice, purpose limitation, storage limitation and security.
Where you are the data controller and we host the platform, we are a processor acting on your instructions. On a self-hosted installation there is no processor at all. This is general information rather than legal advice; confirm your position with your own counsel, particularly if you employ people outside India.
If you believe you have found a security issue, email support@employeedeskcrm.com with the subject line Security. Include enough detail to reproduce it. We will acknowledge, investigate and tell you what we found.
Please do not test against another customer’s data. Self-hosted customers may test their own installation freely; it is your server.
Not today. We are not going to claim a certification we do not hold. The controls described on this page are implemented, and for buyers whose procurement requires certified infrastructure, the self-hosted licence lets you run the application inside an environment that already carries your own certification.
Yes. All traffic uses HTTPS with TLS, and cloud data is encrypted at rest at the storage layer. On a self-hosted installation, encryption at rest is a property of the disk and the host you provide, which is one of the responsibilities that moves to you.
Only roles you grant, and every access is written to an audit log that records which manager opened whose captures and when. The employee can always see their own.
Access is limited to the small number of people who operate the platform, is used only for support and incident response, and is logged. On a self-hosted installation we have no access at all, because there is no route into your network.
We investigate, contain, and notify affected customers with what we know, what we do not yet know and what we are doing about it. For self-hosted installations the incident is yours to manage on your infrastructure; we support the investigation where the application is involved.
Yes: SAML 2.0, OIDC and AD/LDAP directory sync. SSO and directory sync are available on self-hosted and enterprise arrangements.
Tell us what your procurement process needs. We can discuss testing arrangements under NDA, and self-hosted customers are free to test their own installation without asking permission.
If something they need is missing from it, tell us and we will add it here rather than answering it once in an email.