Trust
Security, access and audit
Emplitrack holds attendance, location and employee data. This page is for the people who have to sign off on it.
- Separated per organization,resolved on every request.
- Scoped per role,so a branch manager sees their branch.
- Audited,with legal hold that fails closed.
Separation
One platform, separated data
Each organization's data belongs to that organization, and access is resolved per request against the organization the user belongs to.
- Organizational data scope: a branch manager sees their branch, a department head their department
- Roles describe the job, permissions describe the action, and the two combine
- Platform administration is separate from organization administration
- Authentication runs through a dedicated identity layer, not per application
Audit
The ledger, and what it is for
Important actions are written to a ledger built to be tamper-evident. Records are chained, so a change to history shows up instead of passing unnoticed.
- Legal hold prevents removal while a hold is in place, and fails closed
- A disputed attendance day, answered in a minute
- Who changed an employee record, and when
- Location is treated as sensitive and has its own position statement
Plainly
What we do not claim
Two things we will not imply, because procurement finds out either way.
SOC 2 or ISO 27001 certification today. Where it matters to you, raise it early so timing can be discussed honestly.
GDPR compliance as a label. Compliance is a judgment you make about your own processing. We set out what the platform does, stores and controls so your team can assess it.
Common questions
Where is our data stored?
Deployment location is part of the commercial conversation, because it depends on your region and your requirements. Ask in the demo and you will get a specific answer.
Who at Emplitrack can see our data?
Access is limited to the people who need it to run and support the platform, and platform administration is a separate role from organization administration.
Do you support single sign-on?
Authentication runs through a dedicated identity layer, which is the right foundation for it. Raise SSO early so it can be scoped.