Trust

Security and data protection

Attendance records, work reports and screenshots are employee personal data. This page sets out how that data is protected, who can reach it, what we do not claim, and exactly which responsibilities move to you when you self-host.

  • TLS everywhere
  • Role-based access
  • Access audit log
  • Self-hostable

What we do not claim

Worth putting first, because it is the paragraph most vendor security pages leave out.

Employee Desk does not hold ISO 27001 or SOC 2 certification today. If your procurement process requires a certified platform, the honest options are: run the application on your own certified infrastructure, which is precisely why the self-hosted licence exists; or wait until we hold the certification, and we will publish it here when we do rather than implying it beforehand.

Application security

01

Transport encryption

HTTPS with TLS on every connection, including desktop tracker uploads. HTTP requests are redirected rather than served.

02

Authentication

Password hashing with a modern algorithm, configurable password policy, session expiry and forced re-authentication for sensitive actions. SAML 2.0, OIDC and AD/LDAP directory sync where you need directory integration.

03

Role separation

Employee, manager, HR and admin roles with distinct capabilities. A manager sees their own reports, not the whole company.

04

Access audit log

Who viewed what, and when — including which manager opened whose screenshot gallery. This is the control most monitoring products are missing.

05

File handling

Uploads are type-checked and stored outside the web root. Screenshots are served through authorised requests rather than from a guessable public URL.

06

Data isolation

Tenant scoping on every query on the shared cloud, and dedicated infrastructure on private cloud.

Infrastructure, by deployment model

Who is responsible for what
ControlCloudPrivate cloudSelf-hosted
Host patchingUsUsYou
Application updatesUsUsYou, from published images
Encryption in transitUsUsYou supply the certificate
Encryption at restUsUsYour disk and host configuration
BackupsUs, dailyUs, isolated per instanceYou, documented procedure
Access control inside the appProduct featureProduct featureProduct feature
Network exposureUsUsYou — 443 inbound only
Vendor access to your dataSupport and incident response, loggedSameNone
Sub-processor in your privacy noticeUsUsNone

Technical facts a security reviewer will ask for

Install
Docker Compose, single host
Stack
Node.js application + MongoDB
Minimum server
4 vCPU · 8 GB RAM · 200 GB disk
Ports
443 inbound only
Data leaving your network
A licence check, or none
Screenshot storage
Local disk or your own S3 bucket
Authentication
SAML 2.0, OIDC and AD/LDAP directory sync
Desktop clients
Windows 10/11 · macOS 11+ · Ubuntu 20.04+

Data protection and Indian law

Employee attendance, activity and screenshot data is personal data. Under the Digital Personal Data Protection Act framework, the employer processing it is the entity with obligations to its employees, and the four that matter operationally are notice, purpose limitation, storage limitation and security.

  • Notice. Employees must be told what is collected. The product supports this by design: the tracker is visible, screenshots trigger a notification, and every employee can see their own record. The written policy is still yours to publish.
  • Purpose limitation. Collect what the business purpose needs. If hours are the question, run the tracker with screenshots off — that is a supported configuration, not a degraded one.
  • Storage limitation. Configure retention rather than keeping captures indefinitely.
  • Security. Role-based access, the audit log and, if your policy requires it, keeping the whole system inside your own network.

Where you are the data controller and we host the platform, we are a processor acting on your instructions. On a self-hosted installation there is no processor at all. This is general information rather than legal advice; confirm your position with your own counsel, particularly if you employ people outside India.

Reporting a vulnerability

If you believe you have found a security issue, email support@employeedeskcrm.com with the subject line Security. Include enough detail to reproduce it. We will acknowledge, investigate and tell you what we found.

Please do not test against another customer’s data. Self-hosted customers may test their own installation freely; it is your server.

Security questions

Is Employee Desk ISO 27001 or SOC 2 certified?

Not today. We are not going to claim a certification we do not hold. The controls described on this page are implemented, and for buyers whose procurement requires certified infrastructure, the self-hosted licence lets you run the application inside an environment that already carries your own certification.

Is data encrypted?

Yes. All traffic uses HTTPS with TLS, and cloud data is encrypted at rest at the storage layer. On a self-hosted installation, encryption at rest is a property of the disk and the host you provide, which is one of the responsibilities that moves to you.

Who inside our company can see screenshots?

Only roles you grant, and every access is written to an audit log that records which manager opened whose captures and when. The employee can always see their own.

Do you have access to our data on the cloud?

Access is limited to the small number of people who operate the platform, is used only for support and incident response, and is logged. On a self-hosted installation we have no access at all, because there is no route into your network.

What happens in a security incident?

We investigate, contain, and notify affected customers with what we know, what we do not yet know and what we are doing about it. For self-hosted installations the incident is yours to manage on your infrastructure; we support the investigation where the application is involved.

Do you support single sign-on?

Yes: SAML 2.0, OIDC and AD/LDAP directory sync. SSO and directory sync are available on self-hosted and enterprise arrangements.

Can we get a penetration test report?

Tell us what your procurement process needs. We can discuss testing arrangements under NDA, and self-hosted customers are free to test their own installation without asking permission.

Send this page to your security reviewer

If something they need is missing from it, tell us and we will add it here rather than answering it once in an email.

  • 7-day trial
  • No credit card
  • Cancel anytime