Compliance & Security

How we protect your data, maintain your privacy, and meet the standards required for your trust.

ENC
AES-256 Encryption
Active
TLS
TLS 1.2+ in Transit
Active
SOC2
SOC 2 Readiness
In Progress
GDPR
GDPR / CCPA
Compliant

Data Security

Encryption

  • AES-256 encryption for all stored data
  • TLS 1.2+ for all data in transit
  • Encryption keys rotated quarterly
  • Incident records encrypted per-user with unique keys
  • Passwords hashed with bcrypt (never stored in plaintext)

Access Controls

  • Two-factor authentication (2FA) available for all accounts
  • Role-based access control for internal staff
  • Zero knowledge architecture for incident content
  • Staff cannot access your incident records
  • Privileged access logged and audited

Infrastructure

MyHRProof is hosted on Amazon Web Services (AWS) in the United States. We leverage AWS's security infrastructure, which maintains SOC 1, SOC 2, ISO 27001, and PCI DSS compliance. Our specific infrastructure controls include:

SOC 2 Compliance

MyHRProof is currently building toward SOC 2 Type II certification. SOC 2 is an industry-standard audit framework developed by the American Institute of Certified Public Accountants (AICPA) covering Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Our current SOC 2 readiness includes:

Security (CC6)

  • Logical access controls implemented
  • Multi-factor authentication enforced internally
  • Security awareness training for all staff
  • Penetration testing conducted annually

Availability (A1)

  • 99.9% uptime SLA target
  • Redundant infrastructure across AWS AZs
  • Automated failover configured
  • Incident response plan documented

We expect to complete our SOC 2 Type II audit by Q4 2025 and will publish our report upon certification.

Privacy Compliance

CCPA (California Consumer Privacy Act)

We are a CCPA-compliant business. We do not sell personal information. California residents may exercise their CCPA rights by contacting privacy@myhrproof.com.

GDPR (General Data Protection Regulation)

For users in the European Economic Area and United Kingdom, we process personal data under lawful bases including contract performance and legitimate interest. We maintain Standard Contractual Clauses (SCCs) with all sub-processors. Data subject requests: privacy@myhrproof.com.

COPPA

MyHRProof is not directed to children under 18. We do not knowingly collect personal information from minors.

App Store & Google Play Compliance

Apple App Store Requirements

Google Play Requirements

Vulnerability Disclosure

We maintain a responsible disclosure program. If you discover a security vulnerability in MyHRProof, please report it to security@myhrproof.com. We will acknowledge your report within 48 hours, investigate, and work to resolve the issue. We ask that you:

We do not currently offer a bug bounty program, but we appreciate responsible disclosure and will acknowledge credited researchers upon resolution.

Incident Response

In the event of a security incident affecting your data, we will notify affected users within 72 hours of discovery, describe what happened and what data was affected, explain what we have done to address the incident, and provide guidance on steps you can take to protect yourself. Notifications will be sent to your registered email address and posted to our status page.

Questions

For compliance and security inquiries: security@myhrproof.com