Security

How we protect your payroll data

Payroll is the most sensitive information most businesses hold. Salaries, national ID numbers, and bank details, all in one place. Here is what we do about that, in plain language.

A quiet office desk by a window with a laptop closed on it

What we do not claim

We do not hold ISO 27001, SOC 2 or any similar certification, and we are not going to pretend otherwise. What follows is a plain description of how we look after your information, which you can weigh up for yourself. It is not a stamp from an outside auditor. Security is a shared job, no system anywhere can be promised to be perfect, and we recommend you keep your own copies of anything critical, as our Terms set out.

Your company stays your company

Everything belonging to your business is kept entirely apart from every other business using Internal Payroll. Your figures are never pooled with anyone else's and never sit alongside theirs. If you run several companies, the same applies between each of them.

The sensitive details are protected

National ID numbers and bank account numbers are stored in a protected form rather than as plain text, so they are not readable to somebody who gets hold of a raw copy of the information. You can still search for a person the way you always could.

Separate doors for separate people

Your own staff, your outside clients, and your employees all sign in through completely separate doors with separate accounts. A client checking what you shared with them has no route into your side of things, and an employee looking at a payslip has no route into payroll.

You decide who sees what

Permission is set person by person and it is checked on every action, not just when a page opens. Somebody can be given the job of keeping employee records tidy without ever being shown what a single person earns.

Every change leaves a trace

Sensitive changes are written down as they happen, and those entries cannot be edited or quietly tidied up afterwards. A record of who changed what is only worth keeping if nobody can go back and rewrite it.

When we help, we cannot touch anything

If we need to look at your account to answer a question, that access lets us see what you see and nothing more. We cannot change your payroll while we are in there, and the visit is recorded.

Protected on the way to you

Every page is served over a secure connection with a valid certificate, and anything arriving unsecured is redirected. There is no unprotected way in.

Backed up, and kept somewhere else

Your information is copied on a regular schedule and those copies are kept away from the live service, so a problem with one does not become a problem with the other. We check that the copies actually restore rather than assuming they will.

We never hold your card details

You pay by wire transfer, check, or cash. There is no card number anywhere in the product, which means there is no card number for anyone to lose. The safest way to hold payment details is not to hold them.

The admin side is not a public door

The tools we use to set up and support companies are not linked anywhere on this site, are not reachable by guessing, and sign themselves out when left idle.

Reporting a vulnerability

If you think you have found a security problem, please get in touch and tell us what you found and how to reproduce it. We would far rather hear it from you than not hear it at all, and we will not come after anybody who reports a real issue in good faith.

Payroll you can hand over with confidence

Ask for an account, or try the shared demo first and see for yourself.