Trust & Security

HR, payroll and accounting data is among the most sensitive a company holds. Here is how WorkRight protects it — tenant isolation, strong authentication, encryption, immutable statutory records and India data residency.

Last reviewed: May 2026 · Plain-English summary, not legal advice.

Data protection

WorkRight is multi-tenant by design. Every record — every employee, payslip, leave request, ledger entry and complaint — is scoped by tenant_id, and every query is filtered to your workspace so one company's data is isolated from another's.

  • Strong authentication. Sessions use httpOnly cookies (no token sitting in browser storage for a script to steal), protected by CSRF (double-submit) and TOTP-based two-factor authentication. 2FA is mandatory for the most privileged roles.
  • Encryption. Data is encrypted in transit (HTTPS/TLS) and at rest.
  • Role-based & capability-based access. Access is least-privilege across distinct roles — employee, manager, HR, admin, accountant and ICC member — with capability-based RBAC for fine-grained permissions on top.

Statutory immutability & audit trail

Some records are not meant to be editable. Locked payroll runs and accounting journals are write-once per Companies Act 2013 §128(1) — there is no back-dating or quiet edit path. Statutory artifacts such as salary slips regenerate byte-for-byte identically from the locked snapshot, in line with §128(5).

Every state-changing action across the platform is recorded in an immutable audit log, so there is always a defensible trail of who did what and when.

POSH confidentiality

The POSH module treats Internal Committee (ICC) complaint data as confidential, with access controls aligned to Section 16 of the POSH Act, 2013. Complaint details are restricted to the people who are entitled to see them, not the wider workspace.

DPDP — India's data-protection law

WorkRight is built around the Digital Personal Data Protection Act, 2023. We capture and record consent — employee consent, for example, is stored with a tamper-evident record — and apply data-minimisation in the API and MCP layer with non-PII reads and redacted audit metadata, so automated and AI integrations work without over-exposing personal data.

You are the data fiduciary for your employees and remain responsible for your own notice and lawful-basis obligations; WorkRight is the platform built to help you meet them.

Data residency — hosted in India

Your data is hosted in India, in the Mumbai region. The application runs on Fly.io (bom) and the database on Supabase (ap-south-1). It does not leave the country in the normal course of operation — relevant if data localisation matters to your business or your customers.

Certifications & roadmap

We want to be precise here: WorkRight does notcurrently hold a SOC 2 or ISO 27001 certification. Formal third-party certification is on our roadmap. In the meantime, the controls described on this page are real and in production today, and we're happy to take a security reviewer through them.

Reporting a vulnerability

If you believe you've found a security issue, please tell us. Email support@workright.in with the details and steps to reproduce. We take reports seriously and will work with you on a fix.

Frequently asked questions

Where is my data stored?

In India — the Mumbai region (Fly.io bom + Supabase ap-south-1). It does not leave the country in normal operation.

Is WorkRight DPDP-compliant?

WorkRight is built around the DPDP Act, 2023 — consent capture with tamper-evident records, data-minimisation in the API/MCP layer, and India residency. You remain the data fiduciary for your employees; WorkRight helps you meet your obligations.

Can WorkRight staff see my data?

Access is least-privilege and auditable. Tenant isolation keeps your data separate, and the API/MCP layer minimises exposure. We don't sell your data or use it to train third-party models.

Are payroll records tamper-proof?

Yes — locked payroll runs and accounting journals are write-once per Companies Act §128(1), salary slips regenerate byte-identically per §128(5), and every change is written to an immutable audit log.

Related

Security questions before you sign up?

We're happy to walk a security or compliance reviewer through our posture. Email support@workright.in or start a free trial and see the controls for yourself.