Schema-Per-Tenant
Each organization's data lives in its own PostgreSQL schema. Separation is enforced by that schema boundary and the application's tenant context, not by database policies.
Security you can check rather than an adjective: every organization runs in its own PostgreSQL schema, and our Trust Center lists each certification next to its actual state. Today every one of them reads not evidenced.
Each organization's data lives in its own PostgreSQL schema. Separation is enforced by that schema boundary and the application's tenant context, not by database policies.
All sensitive data encrypted at rest. TLS 1.3 for all data in transit.
Payslips are delivered as password-protected PDF documents, encrypted per recipient.
Every query runs inside a transaction pinned to its tenant schema, and the binding is cleared when the connection is released.
Data retention policies, right-to-erasure tools, and consent management.
Enterprise single sign-on (SAML/OIDC) and two-factor authentication for all users.
See how FriendHRM can support your team's governed HR operations.