Security
Security, in plain language
HR data is personal. Here is how we look after it, what we do today, and what is still on our list.
Multi-factor sign-in
Every account can use an authenticator app. It is required for HR and admin roles, and sensitive actions such as revealing an NIC ask you to confirm it is you again.
Encryption
All traffic uses HTTPS. Passwords are hashed with Argon2id, and sensitive fields such as NIC numbers are encrypted in the database.
Each company kept separate
Every record belongs to one company. That is checked in the application and again by the database itself, and we test it continuously.
Device-bound attendance
Attendance scans are signed by a key that never leaves the enrolled phone. A screenshot of the QR code expires within seconds and cannot be replayed.
Audit trail
Approvals, role changes, corrections, device enrolments and other important actions are recorded with who, what and when. Records cannot be edited.
Sessions and access
Sessions sit in secure cookies the browser keeps from scripts, idle sessions end automatically, and each role sees only what it needs.
Personal Data Protection Act
We design Staffora around the principles of Sri Lanka’s Personal Data Protection Act No. 9 of 2022: collect only what HR needs, limit who can see it and keep a record of access. Consent and data-subject request tools are planned.
Where your data lives
Customer data is hosted in France. The privacy policy names the providers that also handle email and payments.
What we will not claim
No system is unbreakable. We follow recognised practices, have an independent penetration test before launch, and fix what we learn quickly.
Found a security issue?
Please tell us privately so we can fix it before anyone is harmed. We reply within two working days and credit researchers who want it.
staffora.hello@gmail.com
Placeholder address until the domain is live.
See Staffora with your own eyes
Open the live demo as an employee, a manager or HR. Sample data, no sign-up, nothing to install.