Products
HReasily ClassicSimple, fast payroll for a small businessHReasily ProMulti-entity, multi-country, advanced workflowsHReasily PlusEnd-to-end HR, hiring through to payrollCompare plansClassic, Pro and Plus side by side
Modules
PayrollCPF and tax calculated, filed directLeaveApply, approve, and it reaches payrollTime & AttendanceClock-in that turns into a payslipSchedulingShifts and swaps that become payClaimsReimbursed in the next payroll runComplianceStatutory rules, kept currentIntegrationsXero, QuickBooks and the rest
Who it's for
By role
Head of HROne platform for the whole regionCFO and FinancePeople cost you can see and provePayroll and HR OpsOne run, not five filings
By company
Small businessesPayroll done without an HR teamMulti-country and scaling teamsAdd a market, not a vendor
By market
SingaporeMalaysiaIndonesiaThailandHong KongPhilippines
Partners
Payroll Service ProvidersAccountants and advisors who run payroll on HReasily
Resources
BlogPayroll, HR and compliance writingProduct updatesEvery change we ship, datedGuidesPlaybooks and checklists to downloadWebinarsLive sessions and recordings on demandCustomer storiesThe businesses running on HReasilyHReasily AcademyProduct training, at your own pace
Why HReasily
Multi-country payrollSix markets, one runSecurityHow your people data is protectedXeroPayroll posted as a journal, automaticallyQuickBooksEvery run reconciled in your booksAbout HReasilyWho we are and who we build for
Pricing
PricingPer employee, per month
Start freeLog in
Security and trust

Independently audited. Verifiable today.

HReasily holds ISO/IEC 27001:2022 certification and a SOC 2 Type II report, both audited by independent third parties. The certificate is below and the report is one request away.

SOC 2 Type IIAudited over a period, not one date
ISO/IEC 27001:2022Certified information security management
Hosted on AWS, Singapore region
The four pillars

Where your risk actually sits, and what covers it

The same four questions come back in every vendor assessment. These are the answers.

Infrastructure security

The platform runs entirely on AWS in the Singapore region, so employee data stays in Singapore for the buyers who need it to.

  • AWS Singapore region, for both web and the iOS and Android apps
  • Multi-tenancy and multi-instance architecture, depending on the deployment
  • Redundancy measures across the platform for high availability

Application security

Access is the thing that matters in payroll. A login on its own is not enough to reach a salary.

  • Two-factor sign-in using a single-session, time-limited one-time password
  • Role-based access control across 14 granular permissions, bulk-assignable
  • Payslips are password-protected after they are sent, defaulting to the employee ID
  • Integrations use OAuth 2.0; tokens are never exposed in the app or shared onward

Compliance and privacy

A named officer, a written policy, and statutory logic maintained inside the product for each of the six markets.

  • An appointed Data Protection Officer, reachable at [email protected]
  • PDPA-aligned handling, set out in the Privacy Policy
  • The Privacy Policy and Terms together form the Data Processing Agreement
  • Every payroll run, approval, filing and permission change is recorded

Secure engineering and operations

How the software gets built, tested and patched, which is where most real risk lives.

  • Critical security patches applied as soon as practical, with regular preventive maintenance
  • Endpoint protection and current anti-virus on all company and BYOD endpoints
  • Full disk encryption mandatory on every employee laptop and workstation
  • Engineering, Product and QA test together, manually and automatically, throughout
Data handling

The encryption answers, in the form you were asked for

Standards and versions rather than reassurance, so this section can be pasted straight into a vendor assessment.

Data in transitTLS 1.2 and above

HTTPS only. Connections are refused below TLS v1.2. Encrypted end to end using SHA256 ECDSA for signing and SHA256 RSA for compatibility, with authenticated encryption (AEAD).

Data at restAES-256

Every repository holding sensitive commercial or personal data is encrypted at rest, following the cryptographic functions in NIST Special Publication 800-175B.

Employee devicesFull disk encryption

Mandatory on all employee laptops and workstations, alongside endpoint anti-virus.

RetentionPurpose-bound

Data is kept only as long as needed for the purpose it was collected for, plus what legal, accounting and reporting obligations require.

DeletionOn your request

Cancel and you can request account deletion. Export your copy first, because backups and logs then age out under the retention policy rather than being wiped on the day.

Verify it yourself

Everything your compliance team needs, without booking a call

Vendor risk assessments stall when the evidence sits behind a salesperson. It does not here.

Questions

Procurement, answered

Where is our employee data hosted?
On AWS in the Singapore region, for the web application and the iOS and Android apps alike. If data residency in Singapore is a requirement in your assessment, that is the answer to it.
Who has internal access to our data at HReasily?
Employee data is reachable only by an administrator you assign, with the specific roles you give them. Access is role-based across 14 granular permissions rather than all-or-nothing, and every permission change is recorded.
Are you audited by independent third parties?
Yes. ISO/IEC 27001:2022 certification and a SOC 2 Type II report, both from independent auditors. SOC 2 Type II covers a period of operation rather than a single date, which is the distinction most assessments care about. The certificate is linked above; the report is sent on request.
What happens to our data if we cancel?
You can request deletion of the account. Request your copy of the data first, because after deletion the remaining copies in backups and logs age out under the retention policy. The data is yours throughout.
Is two-factor authentication available?
Yes, using a one-time password valid for a single sign-in session and a defined period, so a stolen password on its own does not get anyone in.
How quickly are security patches applied?
Critical and recent patches go on as soon as practical and reasonable, with any delay justified against business requirements, on top of regular preventive maintenance.

Run payroll on a platform your IT team will sign off.

Start free, set the permissions before you load a single salary, and send your assessment team to this page.

New guide
Switching payroll systems?
Keep your YTD, CPF records and IR8A intact through a move.
Read the guide
Offer
Your first month free
Sign up for a paid plan today and the first month is on us.
See the plans