Security at HR247

How we protect your organisation's data. Last updated 2026.

Encryption in transit

All traffic to HR247 is served over HTTPS/TLS. Data moving between your staff's devices and the server is encrypted.

Passwords & authentication

Passwords are never stored in plain text โ€” they are hashed with bcrypt. New staff are required to set their own password on first login. Sessions are protected with signed, http-only cookies and expire after inactivity. Two-factor authentication (2FA) is on our roadmap for the Enterprise tier.

Role-based access & separation of duties

Access is granted by role. Sensitive areas โ€” salaries, bank details, payout credentials and system settings โ€” are restricted to the Owner/Finance. HR manages people data, managers see only their team, and staff see only their own records. These limits are enforced on the server, not just hidden in the interface.

Payment credentials

Payment provider (Paystack) secret keys are stored server-side and never displayed back on screen. HR247 never transmits your keys to third parties, and payouts require explicit approval before any funds move.

Data isolation

Each organisation runs on its own deployment with its own separate database, so one clinic's data is never mixed with another's.

Location integrity

Optional geofenced clock-in restricts attendance to the office perimeter, reducing time fraud, while hybrid and remote staff are handled per person.

Backups

Organisations can export a full encrypted backup of their data at any time, and we recommend a regular backup schedule.

Security is continually improved. To report a concern, use our contact page.