Security
Last updated: 25 September 2026
HR data is some of the most sensitive data a company holds. Here is how SpaxSync protects it.
Isolated workspaces
Every company has its own workspace at its own address. Each request is checked against the workspace it came from, so one company can never sign in to, or read data from, another.
Access control
Admins, HR, managers and employees each see only what their role allows. Passwords are stored as salted hashes, sign-in attempts are rate-limited, and sessions use secure, HTTP-only cookies.
Encryption
All traffic to SpaxSync uses HTTPS. Data is encrypted at rest by our database and storage provider. Employee documents are stored privately and opened through short-lived links.
Audit trail
Sensitive actions — such as changes to salaries, roles and settings — are written to an audit log that is chained so later tampering can be detected.
Integrations
API keys are scoped to what they may access, and webhooks are signed so your systems can verify they came from SpaxSync.
Reporting a problem
If you think you have found a security issue, email [email protected] with the details. Please do not access data that is not yours while testing.