FriendHRM

Security & Compliance

Security you can check rather than an adjective: every organization runs in its own PostgreSQL schema, and our Trust Center lists each certification next to its actual state. Today every one of them reads not evidenced.

Key capabilities

Schema-Per-Tenant

Each organization's data lives in its own PostgreSQL schema. Separation is enforced by that schema boundary and the application's tenant context, not by database policies.

AES-256 Encryption

All sensitive data encrypted at rest. TLS 1.3 for all data in transit.

Encrypted Payslip Delivery

Payslips are delivered as password-protected PDF documents, encrypted per recipient.

Transaction-Scoped Tenant Binding

Every query runs inside a transaction pinned to its tenant schema, and the binding is cleared when the connection is released.

GDPR tooling

Data retention policies, right-to-erasure tools, and consent management.

SSO & 2FA

Enterprise single sign-on (SAML/OIDC) and two-factor authentication for all users.

Ready to get started?

See how FriendHRM can support your team's governed HR operations.

Security & Compliance | FriendHRM