Trust is part of
the platform.
HeyComply brings sensitive workforce information together. We design the shared platform around controlled access, protected data, clear accountability and privacy-conscious decisions.
A shared approach to protecting every app.
Security is handled as a platform responsibility. The same core approach supports Attendance today and is designed to support each future HeyComply app.
Identity & access
Support for Microsoft Entra ID and Google sign-in, with role-based access that helps organisations give people the right level of control.
Tenant-scoped data
Application data is scoped to the relevant organisation so workforce records and administrative actions stay in their intended context.
Protected integrations
Stored integration credentials and secrets are encrypted, while standards-based safeguards protect sign-in transactions.
Auditability
Audit trails support accountability around important access, administrative activity, imports and changes.
Access is checked
at every step.
Authentication is only the start. HeyComply binds identity to the right organisation, applies permissions to actions and supports revocation when access should end.
- 01Verified sign-in
People authenticate through password access or supported identity providers.
- 02Organisation context
Sign-in transactions are bound to the intended tenant and organisational context.
- 03Role-based authorisation
Permissions determine which areas and administrative actions are available.
- 04Revocation when needed
Password resets, password changes and deactivation can invalidate existing sessions.
Designed to use workforce data responsibly.
HeyComply follows a UK GDPR-conscious approach: collect what is needed, protect access to it and keep important activity understandable.
Data minimisation
Product decisions are guided by using the workforce information needed for a clear purpose.
Secure connections
HTTPS/TLS protects information while it travels between users, integrations and HeyComply.
Purpose-bound recovery
Invitation and password reset tokens are purpose-specific, stored as hashes and tracked through use or revocation.
Trust starts with saying
what we can support.
We publish controls and commitments we can stand behind, and we avoid turning security into vague promises. If your organisation has specific security or data questions, speak with our team.
Start a conversation