Skip to main content
SECURITY & PRIVACY

Security is not a badge. It is a set of decisions.

Employee records, payroll data, and vendor contracts are sensitive. This page separates our baseline controls from details that must be confirmed for each implementation.

Price my subscription Ask a security question
Transparency note

We do not claim SOC 2 or ISO 27001 certification on this page. Exact hosting region, retention, recovery objectives, and integration controls are confirmed in the customer scope and service agreement.

01 / Confirmed per project

Data storage

  • Hosting provider and data region are documented before implementation
  • Managed encryption at rest and encrypted transport are required for production data
  • Backup frequency and retention are defined in the service agreement
  • For Supabase deployments, the selected project region is confirmed with the customer
02 / Core design standard

Access control

  • Company-scoped data access is enforced at the database layer
  • Role-based access for owner, admin, HR, finance, manager, and viewer
  • Module-level permissions keep payroll and sensitive documents restricted
  • Privileged service credentials remain server-side and are never shipped to the browser
03 / Core design standard

Audit & compliance

  • Approval decisions record actor, timestamp, status, and supporting context
  • Material record changes are designed to retain ownership and history
  • PDPA requests for access, correction, deletion, and portability follow a documented process
  • Sensitive identifiers and banking data require restricted access and protected storage
04 / Baseline control set

Application security

  • Server-side validation is required on every write endpoint
  • Rate limiting is applied to public submission endpoints
  • Security headers include content-type protection, frame controls, and transport security
  • Dependencies and production configuration are reviewed before launch
05 / Disclosed before launch

Third parties

  • Hosting, database, email, analytics, and calendar providers are listed in the project privacy notice
  • Transactional email providers receive only the data required to deliver the message
  • Analytics is configured to avoid collecting typed sensitive form values
  • We do not sell customer or employee data
SECURITY QUESTIONS

Need a vendor review or architecture answer?

Email security@backofficebuilder.co. We will answer with the controls and assumptions relevant to your proposed system.

Email security