WebHR
Trust

Security at WebHR

How workspaces are kept apart, how data is protected, and how to report a problem.

Last updated: 27 August 2026

Isolation between workspaces

Every workspace is a separate tenant, and separation is enforced in the database itself rather than only in application code. Row-level security is forced on tenant tables, so a query that forgets its tenant filter returns nothing instead of somebody else’s rows. Each request carries the tenant context of the signed-in user for its whole lifetime.

Encryption

All traffic is served over TLS, with certificates issued and renewed automatically — including for customer-owned domains. Data is encrypted at rest on the underlying storage. Credentials are stored as salted one-way hashes and are never recoverable, by us or anybody else.

Access control

Access inside a workspace is governed by a role hierarchy with per-permission granularity, so an approver cannot read payroll and a recruiter cannot see performance reviews. Multi-factor authentication is available on every plan and can be enforced workspace-wide. Enterprise workspaces can bring their own identity provider over SAML and provision accounts through SCIM.

Auditing

Security-relevant actions — sign-in, permission changes, exports, branding and configuration changes, administrative impersonation — are written to an append-only audit log with the actor, the target and the outcome. Workspace administrators can read their own log.

Availability and backups

The database is backed up on a regular schedule with point-in-time recovery, and restores are exercised rather than assumed. Application containers are stateless and replaceable; a failed deployment rolls back to the previously verified release automatically.

Custom domains

A workspace serving WebHR on its own hostname must prove control of that domain with a DNS record before we will issue a certificate for it or serve content on it. Unverified hostnames are refused, which is what stops somebody pointing a domain at us and having us brand it for them.

If there is a breach

If a personal data breach affects a customer’s data, we tell that customer without undue delay and within 48 hours, with what we know and updates as we learn more, so they can meet the 72-hour notice the DPDP Rules and the GDPR require. Where we are the controller ourselves (website visitors and leads), we notify the Data Protection Board of India and the people affected directly on the same timetable.

Reporting a vulnerability

If you believe you have found a security issue, write to security@webhr.in with enough detail to reproduce it. We will acknowledge within two working days and keep you updated until it is resolved. Please give us a reasonable window to fix an issue before disclosing it publicly, and do not access or modify data that is not yours while testing.

Questions about this page? Write to hello@webhr.in or see our contact page.

Ready to make HR feel effortless?

Join 5,000+ companies replacing spreadsheets and legacy HRMS with WebHR. Setup in 7 days. First 14 days free.