---
title: "Trust Centre: how HRHive protects HR records"
canonical_url: https://hrhive.co.uk/security/
content_type: page
summary: HRHive keeps each organisation's data apart, encrypts the most sensitive personal details with a key for each organisation, signs people in without passwords and records important activity in an audit log. This Trust Centre sets out each fact, explains how it works and lists what we do not yet claim.
audiences:
  - employer
  - adviser
jurisdiction: uk
status: published
last_updated: 2026-10-05
---

# How HRHive protects HR records

Facts you can check, not adjectives. Each statement on this page is something HRHive does today, with evidence behind it. Where something is not yet confirmed, we say so.

## What HRHive does today

Each of these is evidenced, and each is explained in the pages further down.

- Each organisation's data is kept apart in the database by row-level security, which applies to every table that holds organisation data.
- Date of birth, National Insurance number and bank details are encrypted individually with AES-256-GCM, using a separate key for each organisation.
- HRHive is served over HTTPS only, with HTTP Strict Transport Security.
- Documents are downloaded through signed links that expire, not through public addresses.
- There are no passwords to steal. People sign in with a one-time link, an emailed code or a passkey.
- Owners and administrators must use a second step when they sign in, either a passkey or an authenticator-app code.
- Sign-in, two-step verification and document signing requests are rate limited.
- The app sends a strict Content Security Policy and cannot be embedded in other websites.
- Important activity is recorded in an audit log that shows who acted, from which device and address, and what changed. The database rejects updates and deletes on audit log entries.
- Downloads of documents, views of right to work evidence and bank details, views of cases and most exports are recorded in the audit log.
- Signed and completed records are locked, and each stored file carries a SHA-256 fingerprint.
- After a right to work check, only the last three characters of the share code are kept.
- Retention periods are set for each kind of record, with legal holds and a destruction log.
- HRHive runs on Cloudflare, with a managed PostgreSQL database and Resend for email. There are no advertising or analytics trackers inside the application.

## Security, area by area

How each part works in plain words, what it means for you, and what we do not claim.

- [Data protection in HRHive](https://hrhive.co.uk/security/data-protection/) — HRHive keeps each organisation's data apart, encrypts date of birth, National Insurance number and bank details, and shows sensitive fields only to the roles that need them. It gives you a retention schedule, legal holds, a destruction log, and trackers for data requests and complaints. Your organisation decides what to record and stays responsible for its own data protection duties.
- [Encryption in HRHive](https://hrhive.co.uk/security/encryption/) — Customer data is encrypted in transit: HRHive is served over HTTPS only, with HTTP Strict Transport Security. Date of birth, National Insurance number and bank details are also encrypted individually, with a separate key for each organisation, and documents are downloaded through signed links that expire. Other data is protected by access controls rather than by additional encryption in the application.
- [Access controls in HRHive](https://hrhive.co.uk/security/access-controls/) — People sign in without passwords, using a one-time link, an emailed code or a passkey, and owners and administrators must use a second step. Each organisation's data is kept apart in the database, and eight roles decide what each person sees. Only people the employer has authorised can complete a right to work check.
- [Audit logs in HRHive](https://hrhive.co.uk/security/audit-logs/) — Important activity is recorded in an audit log that shows who acted, from which device and address, and what changed, and the database rejects updates and deletes on its entries. Document downloads, views of right to work evidence and bank details, case views and most exports are recorded. Signed and completed records are locked.
- [Subprocessors and the services HRHive runs on](https://hrhive.co.uk/security/subprocessors/) — HRHive runs on Cloudflare, with a managed PostgreSQL database and Resend for email. There are no advertising or analytics trackers inside the application. We will name the database provider here once it is confirmed, and add where each service processes data.

## What we do not claim

Some things are not confirmed yet, so we do not say them. When one is confirmed, we will add it to the facts on this page, with the evidence behind it.

- **Where customer data is stored.** We will publish the location once it is confirmed. We will not guess.
- **Backups and recovery.** There is no published backup policy or recovery commitment yet.
- **Encryption at rest by our hosting providers.** We have not yet confirmed it with each provider, so we do not rely on it. The fields HRHive encrypts itself are listed above.
- **Malware scanning.** We do not claim that uploaded files are scanned for malware.
- **Independent testing or certification.** We do not claim an independent penetration test or an independent security certification.
- **Availability.** There is no status page, uptime figure or service level yet. A public status page is planned.
- **More from the audit log than it does.** The database rejects edits and deletions of audit log entries, but the entries are not chained together cryptographically, so we describe the log exactly that way.
- **A vulnerability disclosure policy.** It is not published yet.

## Questions HR buyers ask

### Where is our data stored?

We will publish where customer data is stored on this page once the location is confirmed. Until then we do not state one, because we would rather say nothing than guess. What we can tell you now is which services HRHive runs on: Cloudflare, a managed PostgreSQL database and Resend for email.

### Is our data encrypted?

In transit, yes. HRHive is served over HTTPS only, with HTTP Strict Transport Security. On top of that, date of birth, National Insurance number and bank details are encrypted individually, with a separate key for each organisation. Other data, including uploaded documents, is protected by access controls rather than by additional encryption in HRHive. :link[The encryption page]{to="security:encryption"} explains each layer.

### Can other organisations that use HRHive see our records?

Each organisation's data is kept apart in the database by row-level security, which applies to every table that holds organisation data.

### Who in our organisation can see salary, bank and medical details?

Only the roles that need them. HRHive has eight roles: owner, admin, HR, manager, payroll, compliance, employee and a read-only auditor. Sensitive fields such as bank, salary, National Insurance and medical details are shown only to the roles that need them.

### Can our HR adviser or accountant have access?

Yes. One person can belong to several organisations with a different role in each, and an adviser can be invited into a client's organisation. Right to work checks are different: only someone the employer has authorised, acting under its control, can complete one. An adviser can see status, upload evidence, chase and assign the check.

### Can we see who viewed or changed a record?

Yes. Important activity is recorded in an audit log that shows who acted, from which device and address, and what changed. Downloads of documents, views of right to work evidence and bank details, views of cases and most exports are recorded too. Not every view is recorded, and we do not claim that it is.

### How do people sign in?

Without passwords. People sign in with a one-time link, an emailed code or a passkey. Owners and administrators must also use a second step, either a passkey or an authenticator-app code.

### Do you have a security certification or a penetration test report?

Not one we can show you today, so we do not claim either. When we have independent evidence, we will publish it here.

### Is there a status page or an uptime commitment?

Not yet. A public status page is planned, and we do not publish uptime figures or a service level today.

## See how it works with your own records.

Start free, invite a colleague with a different role and compare what each of you can see.

[Start free](https://app.hrhive.co.uk/sign-in?next=%2Fnew%3Fhh_funnel%3Dsecurity_trust%26hh_route%3Demployer%26hh_goal%3Dfirst_person_added%26hh_page%3Dsecurity)

## About this page

- Last updated: 5 October 2026

## Change history

- 5 October 2026: First published.

Canonical URL: https://hrhive.co.uk/security/
Start with HRHive: https://app.hrhive.co.uk/sign-in?next=%2Fnew%3Fhh_funnel%3Dsecurity_trust%26hh_route%3Demployer%26hh_goal%3Dfirst_person_added%26hh_page%3Dsecurity
