Legal compliance

    Compliance you can rely on

    We operate in line with European regulations on data protection and employee rights.

    GDPR compliance

    We comply with the EU General Data Protection Regulation (2016/679).

    Data Privacy Framework

    We follow the Data Privacy Framework governing EU–US data transfers.

    AI Act

    Aligned with EU Regulation 2024/1689 on AI — transparency, risk assessment and human oversight.

    DORA

    We meet the core requirements of the DORA Regulation (EU) 2022/2554 on digital operational resilience.

    Whistleblower protection

    Our Whistleblowing module complies with EU Directive 2019/1937.

    Physical security

    Enterprise-grade data centres

    Your data lives in state-of-the-art data centres that meet the highest security standards.

    Enterprise-grade servers

    Customer data is stored with leading cloud providers: OVH and Amazon Web Services (AWS).

    EU-based hosting

    Data is hosted in France and Poland, with backups in two separate regions to limit risk.

    Data centre certifications

    Our operators hold ISO 27001, ISO 27017 and ISO 27701 certifications, among others.

    Network security

    Network protection

    Multi-layered network safeguards defend against threats and attacks.

    DDoS protection

    Cloudflare shields our infrastructure from DDoS attacks with advanced mitigation.

    Web Application Firewall (WAF)

    Advanced WAF rules provide multi-layered protection against common web attacks.

    99.95% availability

    Load balancing and infrastructure redundancy keep the service running reliably.

    Check our service status page

    Application security

    Security policy

    Configure security settings to match the policy already in place at your organisation.

    Single Sign-On (SSO)

    SAML, Okta, OneLogin, Google, Microsoft, Slack — choose what fits your organisation.

    Two-factor authentication

    2FA via Google or Microsoft, with flexible policy configuration.

    Flexible permissions

    Permission groups with granular action rights and configurable user roles.

    Login and password policy

    Configure password complexity, rotation and other login parameters.

    Session control

    Set session length, inactivity timeouts and automatic logout.

    Account lockout

    Accounts lock automatically after a defined number of failed login attempts.

    Audit and change log

    Key system events are recorded, giving you full visibility and history.

    Antivirus scanning

    Files are scanned automatically on upload and download.

    Enterprise Security add-on

    Extra, configurable security controls for demanding organisations.

    Data protection

    Comprehensive data protection

    Encryption, backups, isolation and full control over your data's lifecycle.

    Data encryption

    AES-256 for data at rest and TLS for data in transit between server and browser.

    Backups

    Backups run twice a day, minimising data loss and preserving business continuity.

    Multi-tenant architecture

    Separate databases and files with per-account keys for stronger isolation.

    Data deletion

    A transparent deletion procedure applies to both trial and paid accounts.

    Data anonymisation

    We apply anonymisation and pseudonymisation in line with legal requirements.

    Organisational security

    Internal security practices

    Our processes, procedures and training build a strong security culture.

    IT asset management

    We maintain a register of digital and IT assets covered by an access-management procedure.

    Employee training

    Regular training on security and personal data processing.

    HR security

    Recurring training on security, GDPR and AI for all employees.

    Confidentiality

    Employees sign confidentiality agreements and follow privacy and security rules.

    Access management

    A procedure for managing access to digital and IT resources, with regular reviews.

    Business Continuity Planning

    A BCP ensures continuity if key personnel become unavailable.

    Disaster Recovery Plan (DRP)

    A DRP is in place to restore the service after unforeseen incidents.

    Vendor management

    We regularly review vendors and data processors for compliance.

    Penetration testing

    Regular external penetration tests confirm our defences stay up to date.

    Want the latest penetration test certificate? Get in touch.

    Downloadable document

    Security at tomHRM

    We focus on security best practices. Learn about our approach to security, data privacy, compliance and governance.

    FAQ

    Frequently asked questions

    Answers to technical, legal and operational questions about tomHRM security.

    tomHRM and all customer data are hosted within the European Union, in data centres located in France and Poland. We use OVH as our core server infrastructure provider and Amazon Web Services (AWS) S3 for secure file storage. All data centres hold security certifications, including ISO 27001, SOC 2 and SOC 3, and comply with GDPR (EU) 2016/679.