Skip to content

Security

Last updated: 25 September 2026

HR data is some of the most sensitive data a company holds. Here is how SpaxSync protects it.

Isolated workspaces

Every company has its own workspace at its own address. Each request is checked against the workspace it came from, so one company can never sign in to, or read data from, another.

Access control

Admins, HR, managers and employees each see only what their role allows. Passwords are stored as salted hashes, sign-in attempts are rate-limited, and sessions use secure, HTTP-only cookies.

Encryption

All traffic to SpaxSync uses HTTPS. Data is encrypted at rest by our database and storage provider. Employee documents are stored privately and opened through short-lived links.

Audit trail

Sensitive actions — such as changes to salaries, roles and settings — are written to an audit log that is chained so later tampering can be detected.

Integrations

API keys are scoped to what they may access, and webhooks are signed so your systems can verify they came from SpaxSync.

Reporting a problem

If you think you have found a security issue, email [email protected] with the details. Please do not access data that is not yours while testing.