SOC 2 Type II
Independently audited controls for security, availability and confidentiality.
The group’s platforms handle sensitive data for thousands of companies, agencies and temporary workers. Every brand is built and run to keep that data safe.
Security & Trust
Independently audited controls for security, availability and confidentiality.
Certified since 2017 and extended across the group’s entities, covering the information security management system.
Client data is encrypted both while it’s moving and while it’s stored, using current industry-standard methods.
Built for local data protection laws, with tools that help clients meet their own obligations.
Infrastructure & hosting
An externalized SOC monitors the platforms 24/7, backed by a security-first engineering culture.
Strict application-level isolation with row-level security and role-based access. No client can reach another client’s data.
External audits and independent penetration tests run alongside ISO 27001 certification, so security is proven in practice. Continuity plans are tested every year.
Data control
Access control
Multi-factor authentication, single sign-on and Zero Trust controls govern who can reach data, with every action logged.
Vulnerability management
Independent external teams run regular penetration tests to find and fix weaknesses before they become risks.
Vendor accountability
Every external partner meets the same security requirements as the group, so no third party becomes the weak point.
Dig into the details