Security & Data Handling

One-page security summaryfor IT & compliance teams.

Everything your InfoSec, DPO or procurement contact needs to know about how MySalaryPal protects payroll data — in a single screen.

Data residency

EU — Frankfurt, DE

Encryption

AES-256 / TLS 1.2+

Breach SLA

72 hours

Backups

7-day PITR

Hosting & Data Residency

  • Cloudflare EU edge network — all traffic routed through European edge nodes.
  • Supabase database and file storage hosted in the EU region (Frankfurt, DE).
  • No US data processing for core payroll data. AI explanations are opt-in and use EU-region providers.
  • Sub-processors: Cloudflare (edge/WAF), Supabase (database/auth/storage), Paddle (payments), Resend (email).

Access Control

  • Row-Level Security (RLS) enforced on every database table — no exceptions.
  • user_roles table with has_role() SECURITY DEFINER function prevents recursive RLS issues.
  • Authentication: email/password, Google SSO, and SAML workspace-level SSO.
  • Passkeys (Face ID, Touch ID, Windows Hello, device PIN) as phishing-resistant second factor.
  • Role separation: employee, HR, payroll, admin, owner — enforced at the database layer.

Audit & Tamper Evidence

  • SHA-256 hash-chained audit log: every payslip view, upload, admin action and change request is logged.
  • Immutable logs with user ID, timestamp, IP address and action type.
  • Full audit chain verification — detect tampering by re-computing the hash chain.
  • CSV export available to workspace admins for compliance reviews.

GDPR & Self-Serve

  • Employee data export as structured JSON — no email tickets, no delays.
  • 30-day deletion guarantee per Article 17 (right to erasure).
  • Data Processing Agreement (DPA) available at /legal/MySalaryPal-DPA.pdf — pre-signed, ready to counter-sign.
  • DPIA template available at /legal/MySalaryPal-DPIA-Template.pdf — drop-in for your DPO records.
  • Lawful basis: Article 6(1)(b) — contract performance for payroll processing.

Application Security

  • Zod schema validation on every API input — prevents injection and malformed data.
  • Parameterized queries via Supabase client — no raw SQL injection vectors.
  • Webhook endpoints verify HMAC-SHA256 signatures before processing.
  • Cloudflare Turnstile CAPTCHA on demo and sign-up flows to block automated abuse.
  • Secrets stored in platform-managed secret manager — never in source code.
  • security.txt at /.well-known/security.txt with 2-day response commitment.

Operational Security

  • TLS 1.2+ for all data in transit.
  • AES-256 encryption at rest for database and file storage.
  • 7-day point-in-time recovery via automated backups (RPO ≤ 5 min, RTO ≤ 4 hours).
  • 72-hour breach notification to affected customers (GDPR Article 33 compliant).
  • Rate limiting and anomaly detection on authentication endpoints.
  • Cyber Essentials Plus certification in progress (target Q1 2026). Independent penetration test scheduled Q1 2026 — executive summary published on request.
  • SOC 2 Type II and ISO 27001 planned as post-pilot, revenue-funded initiatives.

Personnel Security (HR)

  • All staff and contractors sign an NDA and confidentiality agreement before any access to customer environments.
  • Background checks for anyone with production access, proportionate to role and jurisdiction.
  • Annual security & GDPR awareness training; role-based training for engineering and support.
  • Access is provisioned on a least-privilege, need-to-know basis and reviewed quarterly.
  • Documented joiner/mover/leaver process — access revoked within 24 hours of role change or departure.
  • Disciplinary process in place for security policy violations.

Endpoint & Device Management

  • Company-managed endpoints with full-disk encryption (FileVault / BitLocker) enforced.
  • Screen-lock, strong password and biometric unlock required on all devices with production access.
  • OS and browser auto-update enforced; end-of-life OS versions blocked from admin consoles.
  • Endpoint protection / anti-malware on every device that can reach production.
  • Remote wipe capability for lost or stolen devices with cached credentials.
  • No customer payroll data is stored locally in the normal course of operations — access is through the browser-based admin console.

Compliance posture

MySalaryPal is designed for employers across Europe. We align with:

  • GDPR (EU 2016/679)
  • UK GDPR & Data Protection Act 2018
  • Irish Data Protection Act 2018
  • ePrivacy Regulations
  • EU Pay Transparency Directive (2023/970) ready
  • PCI-DSS via Paddle (Merchant of Record)
  • Data Processing Agreement signed before production data flows.
  • Sub-processor list reviewed periodically; material changes notified 30 days in advance.
  • International transfers use 2021 Standard Contractual Clauses (Module 3) where applicable.

Sub-processors

A short, deliberate list. All EU-hosted where the option exists.

VendorPurposeRegionSafeguard
SupabaseDatabase, auth, file storageEU (Frankfurt)DPA + EU region
CloudflareEdge delivery, DDoS, WAFGlobal edgeSCC + DPA
PaddlePayments (Merchant of Record)EU / UKPCI-DSS L1 + DPA
ResendTransactional emailEUDPA
Google GeminiPayslip explanations (opt-in)EU multi-regionSCC, no training
OpenAIPayslip explanations (opt-in)USSCC, zero-retention

AI explanations are opt-in per workspace. Inputs and outputs are not used to train public models.

Documents — ready to share

Download the one-page summary, DPA and DPIA templates your IT, DPO or procurement contact needs.

Reporting a security concern

If you believe you've found a vulnerability or have a security question, email hello@mysalarypal.com. We acknowledge reports within one business day.