Trust & security

Trust is part of
the platform.

HeyComply brings sensitive workforce information together. We design the shared platform around controlled access, protected data, clear accountability and privacy-conscious decisions.

HCTrust foundation
IdentityAccessPrivacyAudit
EUHosted in the European Union
SSOMicrosoft and Google sign-in support
RBACRole-based access controls
ICORegistered · ZC159458
Platform-wide controls

A shared approach to protecting every app.

Security is handled as a platform responsibility. The same core approach supports Attendance today and is designed to support each future HeyComply app.

Identity & access

Support for Microsoft Entra ID and Google sign-in, with role-based access that helps organisations give people the right level of control.

Tenant-scoped data

Application data is scoped to the relevant organisation so workforce records and administrative actions stay in their intended context.

Protected integrations

Stored integration credentials and secrets are encrypted, while standards-based safeguards protect sign-in transactions.

Auditability

Audit trails support accountability around important access, administrative activity, imports and changes.

Access lifecycle

Access is checked
at every step.

Authentication is only the start. HeyComply binds identity to the right organisation, applies permissions to actions and supports revocation when access should end.

  1. 01
    Verified sign-in

    People authenticate through password access or supported identity providers.

  2. 02
    Organisation context

    Sign-in transactions are bound to the intended tenant and organisational context.

  3. 03
    Role-based authorisation

    Permissions determine which areas and administrative actions are available.

  4. 04
    Revocation when needed

    Password resets, password changes and deactivation can invalidate existing sessions.

Privacy & governance

Designed to use workforce data responsibly.

HeyComply follows a UK GDPR-conscious approach: collect what is needed, protect access to it and keep important activity understandable.

01

Data minimisation

Product decisions are guided by using the workforce information needed for a clear purpose.

02

Secure connections

HTTPS/TLS protects information while it travels between users, integrations and HeyComply.

03

Purpose-bound recovery

Invitation and password reset tokens are purpose-specific, stored as hashes and tracked through use or revocation.

Clear by design

Trust starts with saying
what we can support.

We publish controls and commitments we can stand behind, and we avoid turning security into vague promises. If your organisation has specific security or data questions, speak with our team.

Start a conversation