Security
Security is a property of how the product is built, not a page
This page describes the controls that exist in OsmicPeople today. We do not claim certifications we do not hold; ask us for the current status of any assessment.
Invite-only accounts
No self-service sign-up into a workspace. Administrators invite people; invitations expire.
Strong sign-in
Password policy enforced server-side, two-factor authentication (authenticator app or email code) and passkeys.
Per-device sessions
Every sign-in is a session you can see and revoke. Password changes and offboarding revoke all sessions.
Tenant isolation
Every record is scoped to your company at the database query level. Your workspace address is verified on every request.
Least privilege
Admin, HR, manager and employee roles with per-permission custom roles. Managers never see salary, bank or identity data.
Audit trail
Logins, sensitive reads, corrections, payroll transitions and admin changes are recorded with who, what and when.
Protected files
Documents, payslips and CVs are served through signed, relationship-checked URLs — never public links.
Transport and headers
TLS everywhere, HSTS, strict content-security and referrer policies, rate limiting on authentication endpoints.
Payments by Stripe
Card details never touch OsmicPeople. Billing runs on Stripe Checkout and the Stripe customer portal.
Responsible disclosure
Found something?
Report security issues to support@osmicpeople.com. We acknowledge reports within two working days and will keep you informed while we fix the problem. Please do not test against workspaces you do not own.
Contact the security team