HReasily holds ISO/IEC 27001:2022 certification and a SOC 2 Type II report, both audited by independent third parties. The certificate is below and the report is one request away.
The same four questions come back in every vendor assessment. These are the answers.
The platform runs entirely on AWS in the Singapore region, so employee data stays in Singapore for the buyers who need it to.
Access is the thing that matters in payroll. A login on its own is not enough to reach a salary.
A named officer, a written policy, and statutory logic maintained inside the product for each of the six markets.
How the software gets built, tested and patched, which is where most real risk lives.
Standards and versions rather than reassurance, so this section can be pasted straight into a vendor assessment.
HTTPS only. Connections are refused below TLS v1.2. Encrypted end to end using SHA256 ECDSA for signing and SHA256 RSA for compatibility, with authenticated encryption (AEAD).
Every repository holding sensitive commercial or personal data is encrypted at rest, following the cryptographic functions in NIST Special Publication 800-175B.
Mandatory on all employee laptops and workstations, alongside endpoint anti-virus.
Data is kept only as long as needed for the purpose it was collected for, plus what legal, accounting and reporting obligations require.
Cancel and you can request account deletion. Export your copy first, because backups and logs then age out under the retention policy rather than being wiped on the day.
Vendor risk assessments stall when the evidence sits behind a salesperson. It does not here.
The certificate itself, as issued. Open it, check the scope and the dates.
Open the PDF →Requested through support and sent to you directly, since the report is not public.
Request the report →The third-party services that process customer data, listed rather than described.
See the list →How independent researchers report a vulnerability to us, and what happens next.
Read the policy →The Privacy Policy and the Terms and Conditions together serve as the DPA.
Privacy Policy →A named officer oversees privacy and compliance. Questions go straight there.
[email protected] →Start free, set the permissions before you load a single salary, and send your assessment team to this page.