Skip to content
OsmicPeople

Security

Security is a property of how the product is built, not a page

This page describes the controls that exist in OsmicPeople today. We do not claim certifications we do not hold; ask us for the current status of any assessment.

Invite-only accounts

No self-service sign-up into a workspace. Administrators invite people; invitations expire.

Strong sign-in

Password policy enforced server-side, two-factor authentication (authenticator app or email code) and passkeys.

Per-device sessions

Every sign-in is a session you can see and revoke. Password changes and offboarding revoke all sessions.

Tenant isolation

Every record is scoped to your company at the database query level. Your workspace address is verified on every request.

Least privilege

Admin, HR, manager and employee roles with per-permission custom roles. Managers never see salary, bank or identity data.

Audit trail

Logins, sensitive reads, corrections, payroll transitions and admin changes are recorded with who, what and when.

Protected files

Documents, payslips and CVs are served through signed, relationship-checked URLs — never public links.

Transport and headers

TLS everywhere, HSTS, strict content-security and referrer policies, rate limiting on authentication endpoints.

Payments by Stripe

Card details never touch OsmicPeople. Billing runs on Stripe Checkout and the Stripe customer portal.

Responsible disclosure

Found something?

Report security issues to support@osmicpeople.com. We acknowledge reports within two working days and will keep you informed while we fix the problem. Please do not test against workspaces you do not own.

Contact the security team