Techinvenso
Compliance & Legal Policy

Enterprise Security Architecture & Compliance Whitepaper

Last Updated: September 2026 • Version 2.0 • PulseHR Governance Framework

1. Data Isolation & Relational Hardening

Every database query within PulseHR automatically enforces organization-level scoping via SQL filtering and foreign key validation. Cross-tenant data leakage is architecturally impossible even in the event of malformed client payloads.

2. Cryptographic Encryption Standards

All data in transit is protected using TLS 1.3 encryption with modern cipher suites. Data at rest is encrypted using AES-256 with tenant-isolated customer managed keys (CMK) supported on Enterprise tiers. All uploaded documents are stored in secure S3/Cloudflare R2 object stores with pre-signed, expiring download URLs.

3. Authentication, Lockout Protection & Session Revocation

PulseHR implements Argon2id / bcrypt password hashing with automatic salt rotation. Brute-force protection automatically locks accounts for 30 minutes following 5 consecutive failed login attempts. User password resets instantly revoke all existing JWT session tokens via atomic token_version increments.

4. Immutable Audit Logs & Governance

Every critical action—including payroll run finalizations, approval decisions, recruiter score overrides, and document deletions—is recorded in append-only audit tables with immutable timestamps and actor identifiers.

Have compliance or security questions?

Our security team responds to all inquiries within 24 hours.

Contact Security Team