Our approach to security,
compliance and governance.
GDPR, DORA and AI Act compliant · EU servers · Independent EU-owned company
We operate in line with European regulations on data protection and employee rights.
We comply with the EU General Data Protection Regulation (2016/679).
We follow the Data Privacy Framework governing EU–US data transfers.
Aligned with EU Regulation 2024/1689 on AI — transparency, risk assessment and human oversight.
We meet the core requirements of the DORA Regulation (EU) 2022/2554 on digital operational resilience.
Our Whistleblowing module complies with EU Directive 2019/1937.
Your data lives in state-of-the-art data centres that meet the highest security standards.
Customer data is stored with leading cloud providers: OVH and Amazon Web Services (AWS).
Data is hosted in France and Poland, with backups in two separate regions to limit risk.
Our operators hold ISO 27001, ISO 27017 and ISO 27701 certifications, among others.
Multi-layered network safeguards defend against threats and attacks.
Cloudflare shields our infrastructure from DDoS attacks with advanced mitigation.
Advanced WAF rules provide multi-layered protection against common web attacks.
Load balancing and infrastructure redundancy keep the service running reliably.
Check our service status page
Configure security settings to match the policy already in place at your organisation.
SAML, Okta, OneLogin, Google, Microsoft, Slack — choose what fits your organisation.
2FA via Google or Microsoft, with flexible policy configuration.
Permission groups with granular action rights and configurable user roles.
Configure password complexity, rotation and other login parameters.
Set session length, inactivity timeouts and automatic logout.
Accounts lock automatically after a defined number of failed login attempts.
Key system events are recorded, giving you full visibility and history.
Files are scanned automatically on upload and download.
Extra, configurable security controls for demanding organisations.
Encryption, backups, isolation and full control over your data's lifecycle.
AES-256 for data at rest and TLS for data in transit between server and browser.
Backups run twice a day, minimising data loss and preserving business continuity.
Separate databases and files with per-account keys for stronger isolation.
A transparent deletion procedure applies to both trial and paid accounts.
We apply anonymisation and pseudonymisation in line with legal requirements.
Our processes, procedures and training build a strong security culture.
We maintain a register of digital and IT assets covered by an access-management procedure.
Regular training on security and personal data processing.
Recurring training on security, GDPR and AI for all employees.
Employees sign confidentiality agreements and follow privacy and security rules.
A procedure for managing access to digital and IT resources, with regular reviews.
A BCP ensures continuity if key personnel become unavailable.
A DRP is in place to restore the service after unforeseen incidents.
We regularly review vendors and data processors for compliance.
Regular external penetration tests confirm our defences stay up to date.
Want the latest penetration test certificate? Get in touch.
All key documents are publicly available and kept up to date.
The full terms governing the scope, parameters and mutual rights and obligations of tomHRM and the customer.
View documentThe agreement setting out the rights and obligations of the controller and the processor.
View documentHow we process personal data when you use our website, newsletter and marketing materials.
View documentWe focus on security best practices. Learn about our approach to security, data privacy, compliance and governance.
Answers to technical, legal and operational questions about tomHRM security.