Security
Staffena holds employee records — the most sensitive thing most companies keep about the people who work for them. This is how they are separated, who can reach them, and what we have not done.
One company cannot see another
Every table carries the company it belongs to, and every table has row-level security switched on. The rules are enforced by the database rather than by the application, so a mistake in a page cannot widen them: a query that forgets to filter returns nothing rather than somebody else's rows. A test suite signs in as each kind of person and asserts what they can reach, and it runs on every change.
And inside a company, only what the role allows
Seven roles, from the founder to an employee, each with a scope rather than a list of screens: a team lead sees their own team's work and nobody's pay, a department administrator sees their department. Pay is the one thing no role can be granted — it belongs to the owner and the company's administrators, and two database triggers refuse to store a grant that says otherwise. A field a company defines can be marked HR-only, and the value is a row rather than a key, so it is hidden in exports and in the API as well as on the screen.
Getting in
- Passwords are held by the authentication service and never reach us.
- A second step can be required, and a company can require it of everybody who administers it.
- Single sign-on with Google or Microsoft, where a company uses one.
- Every session is a verified token checked against the authentication server on each request, not a cookie taken at its word.
What is written down
Who changed what, as an append-only trail. Leave decisions and published payslips in particular cannot be rewritten — a mistake is an amendment that names what it replaces, so the history stays true. Support sessions, where our own staff enter a company to help, are logged as they happen and shown to that company.
In transit and at rest
Everything is served over TLS with strict transport security. Each response carries a content-security policy with a nonce minted for that request, so an injected script has nothing to run under. Data is encrypted at rest by the database provider. The product may not be framed by another site, and the only hosts a browser talks to are ours and the company's own database project.
Your data is yours
A company sets how long each kind of record is kept, inside the limits the law sets, and the sweeps run on that schedule. Everything held about one person can be produced as a file from inside the product, and a person can be erased — what the company is required to keep is kept, named, with the reason printed rather than summarised as “some data was retained”. Who processes data on our behalf is listed on the sub-processors page.
What we have not done
We hold no SOC 2 report and no ISO 27001 certificate, and we will not imply otherwise. Staffena is a young product; what is written above is checkable, and a certificate is a thing we would have to earn rather than a thing we can claim. If your procurement requires one, tell us — it changes what we build next.
Telling us about a problem
Write to security@staffena.com. We will acknowledge within one working day. We do not currently run a paid bounty; we do credit people who tell us about something real, if they want to be named.

