Employee Cycle — Site Nav v2
Security & trust

You're handing us the most sensitive data in the company.

Compensation, tenure, demographics, exits. We treat it that way — audited controls, read-only connections, and access that stays locked down by default.

SOC 2 Type 2Sensiba San Filippo
GDPR & CCPAPrivacy compliance
NIST CSFFramework aligned
MonitoredContinuously, via Drata
  1. At the connection

    Read-only, one direction

    Every integration is a one-way API sync authorized by you. We never write back to your system of record, so nothing we do can alter or corrupt your source.

  2. In transit

    Encrypted on the way over

    Workforce data is encrypted as it moves between your systems and ours, and stays encrypted once it lands in storage.

  3. At rest

    Private key access control

    Access to connected data is gated by private key, not by shared credentials passed between systems or stored in a config file.

  4. On the way out

    Permissioned by default

    Leaders see their own people and nothing more. Compensation and PII are gated separately, so a manager viewing headcount doesn’t automatically see salaries.

  5. Continuously

    Monitored, not just audited once

    Our security program is structured against the NIST Cybersecurity Framework, tracked continuously through Drata, and audited by Sensiba San Filippo.

Just as important

What we never do with your data.

Security is as much about what a vendor can't do as what they can.

Never write to your system of recordThe connection is one-way. Your HRIS is the source of truth and stays untouched.
Never leave raw exports lying aroundNo spreadsheets of employee records emailed between people and forgotten in inboxes.
Never expose comp or PII by defaultSensitive fields are gated separately. A manager seeing headcount doesn't automatically see salaries.
Never lock you inRevoke our access from your HRIS at any time and the sync stops. No negotiation required.
For your security reviewer

The questions IT always asks.

If you're filling in a vendor assessment, start here.

What access does Employee Cycle need to our HRIS?

Read-only API access, authorized by you. No write permissions, no admin credentials shared over email or Slack, and no IT ticket required to set it up. You can revoke access from your HRIS at any time.

Are you SOC 2 audited?

Yes. Our SOC 2 audit is performed by Sensiba San Filippo, and our controls are continuously monitored through Drata rather than checked once a year.

How is our data encrypted?

Workforce data is encrypted both in transit and at rest, with access to connected data gated by private key control.

Who inside our company can see what?

You decide. Access is scoped by role, so a department head sees their own people and nothing further. Compensation and PII are permissioned separately from headcount and turnover.

Do you meet GDPR and CCPA requirements?

Yes. See our privacy policy for how personal data is collected, used, and retained.

Can we get a copy of your SOC 2 report?

Get in touch and we'll walk your security team through it. Contact us to request documentation.

Running a vendor assessment?

Send us your questionnaire and we’ll turn it around — or get your security team on a call with ours. We’d rather answer properly than have you guess from a web page.

See it for yourself

Connect one system and judge it directly.

Read-only, revocable, and live in a day. The fastest way to evaluate how we handle your data is to watch us do it.

Always Secure, Private and Compliant

Employee Cycle’s team of HR data experts are certified, compliant and able to ensure a safe space for your HR data connectivity and storage.

GDPR and CCPA Compliance
Encryption at rest and in-transit
Built on NIST CyberSecurity Framework
Private Key Access Control
Professional HR Manager giving OK sign