Trust Centre
How HRHive protects HR records
Facts you can check, not adjectives. Each statement on this page is something HRHive does today, with evidence behind it. Where something is not yet confirmed, we say so.

The facts
What HRHive does today
Each of these is evidenced, and each is explained in the pages further down.
Each organisation's data is kept apart in the database by row-level security, which applies to every table that holds organisation data.
Date of birth, National Insurance number and bank details are encrypted individually with AES-256-GCM, using a separate key for each organisation.
HRHive is served over HTTPS only, with HTTP Strict Transport Security.
Documents are downloaded through signed links that expire, not through public addresses.
There are no passwords to steal. People sign in with a one-time link, an emailed code or a passkey.
Owners and administrators must use a second step when they sign in, either a passkey or an authenticator-app code.
Sign-in, two-step verification and document signing requests are rate limited.
The app sends a strict Content Security Policy and cannot be embedded in other websites.
Important activity is recorded in an audit log that shows who acted, from which device and address, and what changed. The database rejects updates and deletes on audit log entries.
Downloads of documents, views of right to work evidence and bank details, views of cases and most exports are recorded in the audit log.
Signed and completed records are locked, and each stored file carries a SHA-256 fingerprint.
After a right to work check, only the last three characters of the share code are kept.
Retention periods are set for each kind of record, with legal holds and a destruction log.
HRHive runs on Cloudflare, with a managed PostgreSQL database and Resend for email. There are no advertising or analytics trackers inside the application.
In detail
Security, area by area
How each part works in plain words, what it means for you, and what we do not claim.
Data protection
HRHive keeps each organisation's data apart, encrypts date of birth, National Insurance number and bank details, and shows sensitive fields only to the roles that need them. It gives you a retention schedule, legal holds, a destruction log, and trackers for data requests and complaints. Your organisation decides what to record and stays responsible for its own data protection duties.
Read more →Encryption
Customer data is encrypted in transit: HRHive is served over HTTPS only, with HTTP Strict Transport Security. Date of birth, National Insurance number and bank details are also encrypted individually, with a separate key for each organisation, and documents are downloaded through signed links that expire. Other data is protected by access controls rather than by additional encryption in the application.
Read more →Access controls
People sign in without passwords, using a one-time link, an emailed code or a passkey, and owners and administrators must use a second step. Each organisation's data is kept apart in the database, and eight roles decide what each person sees. Only people the employer has authorised can complete a right to work check.
Read more →Audit logs
Important activity is recorded in an audit log that shows who acted, from which device and address, and what changed, and the database rejects updates and deletes on its entries. Document downloads, views of right to work evidence and bank details, case views and most exports are recorded. Signed and completed records are locked.
Read more →Subprocessors
HRHive runs on Cloudflare, with a managed PostgreSQL database and Resend for email. There are no advertising or analytics trackers inside the application. We will name the database provider here once it is confirmed, and add where each service processes data.
Read more →Being clear
What we do not claim
Some things are not confirmed yet, so we do not say them. When one is confirmed, we will add it to the facts on this page, with the evidence behind it.
- Where customer data is stored. We will publish the location once it is confirmed. We will not guess.
- Backups and recovery. There is no published backup policy or recovery commitment yet.
- Encryption at rest by our hosting providers. We have not yet confirmed it with each provider, so we do not rely on it. The fields HRHive encrypts itself are listed above.
- Malware scanning. We do not claim that uploaded files are scanned for malware.
- Independent testing or certification. We do not claim an independent penetration test or an independent security certification.
- Availability. There is no status page, uptime figure or service level yet. A public status page is planned.
- More from the audit log than it does. The database rejects edits and deletions of audit log entries, but the entries are not chained together cryptographically, so we describe the log exactly that way.
- A vulnerability disclosure policy. It is not published yet.
Questions HR buyers ask
Where is our data stored?
Is our data encrypted?
Can other organisations that use HRHive see our records?
Who in our organisation can see salary, bank and medical details?
Can our HR adviser or accountant have access?
Can we see who viewed or changed a record?
How do people sign in?
Do you have a security certification or a penetration test report?
Is there a status page or an uptime commitment?
See how it works with your own records.
Start free, invite a colleague with a different role and compare what each of you can see.