MySalaryPal is an early-stage platform, and we'd rather be precise than impressive. Below is what is in place today, what our infrastructure providers give us, and what is still on the roadmap.
Payroll data is stored in the European Union (Frankfurt) and served from EU edge locations. Only routing and log metadata may pass through non-EU edge points of presence, under SCCs.
TLS 1.2+ in transit, AES-256 at rest. Payslip files and database backups are encrypted by default.
Payroll, HR and employee roles are separated. People only see what their role allows — enforced at the database layer.
Face ID, Touch ID, Windows Hello or your device PIN as a second factor — phishing-resistant by design.
Every payslip view, upload, change request and admin action is logged with user, time and IP.
Managed database backups with point-in-time recovery, provided by our EU-hosted infrastructure provider.
DPA available on request. Subject access, export and erasure flows are built into the product — no email tickets required.
Production access is restricted, MFA-enforced, and reviewed. We don't read your payslip data in the course of normal operations.
Automated monitoring, rate limiting and anomaly detection help identify suspicious activity and protect customer data.
Security incidents are investigated promptly and affected customers are notified where required by law.
Data residency
EU — Frankfurt, DE
Database, file storage and backups all stay inside the European Union.
Breach SLA
72 hours
Customer notification within 72 hours of confirmed personal-data breach (GDPR Art. 33).
Encryption
AES-256 / TLS 1.2+
At rest and in transit, as provided by our EU-hosted infrastructure and storage providers.
Backup & recovery
Point-in-time recovery
Managed backups with point-in-time recovery. Formal recovery-time objectives will be published once independently validated.
MySalaryPal is designed for employers across Europe, and built to align with:
A short, deliberate list. All EU-hosted where the option exists.
| Vendor | Purpose | Region | Attestations |
|---|---|---|---|
| Supabase | Database, auth, file storage | EU (Frankfurt) | SOC 2 Type II, HIPAA, ISO 27001 |
| Cloudflare | Edge delivery, DDoS, WAF | Global edge (EU PoPs) | SOC 2 Type II, ISO 27001, PCI-DSS |
| Paddle | Payments (Merchant of Record) | EU / UK | PCI-DSS Level 1, SOC 2 Type II |
| Lovable | Application platform, transactional email & AI Gateway | EU edge | DPA |
| Google Gemini | Payslip data extraction & explanations (via Lovable AI Gateway) | EU multi-region | SOC 2/3, ISO 27001/17/18, SCC — no training on inputs |
AI explanations are opt-in per workspace. Inputs and outputs are not used to train public models. Vendor names link to their public trust / security pages so your InfoSec team can pull the latest attestation reports directly.
No NDA required. Download our pre-signed DPA and the DPIA template your DPO can drop straight into your records.
GDPR Art. 28-compliant DPA with sub-processor list, SCC reference and Annex II technical measures. Pre-signed for the Processor — counter-sign and return.
PDF · ~4 pages · v1.0
Article 35 DPIA pre-filled with the MySalaryPal context — your DPO only fills in the bracketed sections specific to your rollout.
PDF · ~2 pages · v1.0
If you believe you've found a vulnerability or have a security question, email hello@mysalarypal.com. We acknowledge reports within one business day.