Enterprise-grade security.
Compliant by design.

Your employees' data is the most sensitive asset your organisation holds. We treat it that way.

ISO 27001Information Security
DPDP Act 2023Data Protection
SOC 2 Type IIIn Progress

Encryption at Rest & Transit

All data encrypted with AES-256 at rest and TLS 1.3 in transit. Database connections use SSL. Payslip PDFs are generated server-side and never cached in browser storage.

Data Residency — India

All data for Indian organisations is stored exclusively on servers in India (AWS Mumbai / Azure West India). No employee PII leaves Indian jurisdiction. Singapore and Malaysia data follows local residency rules.

Aadhaar Data Vault

Aadhaar numbers are never stored in the application database. We use a separate encrypted Aadhaar Data Vault with tokenisation. Only tokens are referenced in employee records.

PII Redaction for AI

Before any data is sent to LLM providers (Claude), all personally identifiable information is stripped. ORIS AI never sees employee names, Aadhaar, PAN, or bank details.

Immutable Audit Trail

Every payroll event is recorded in an append-only, event-sourced ledger with hash-chain verification. Corrections are made via compensating events — history is never overwritten.

DPDP Act Compliance

Fully compliant with the Digital Personal Data Protection (DPDP) Act, 2023. PeopleOS acts as Data Processor; your organisation remains the Data Fiduciary. Data portability requests processed within 30 days.

Have security questions?

Our security team is happy to walk through our practices in detail.