Role-based permissions
Company Admin, HR Admin, manager and employee roles determine exactly what each person can see and do.
Security
PHI HR holds sensitive people data. These are the controls in place today — described plainly, with no claims we cannot evidence.
Company Admin, HR Admin, manager and employee roles determine exactly what each person can see and do.
Every table is company-scoped and membership-gated with row-level security enabled, so a user can only ever reach records belonging to a company they are a member of.
Your employee data is stored in the United Kingdom, in AWS London. The web application itself is served over a global edge network, so we describe PHI HR as having UK data storage rather than claiming the whole service runs only in the UK.
Delegated administrators, such as a Contracts Officer, are restricted at database level and provably cannot reach bank details, identity documents or pay data.
Documents are stored securely and released only to users whose role permits access. Deletion is request-and-approve, and replacements retain the original.
Company-level and per-domain audit events are recorded across contracts, leave, documents and training, supporting review and accountability.
Signed contracts retain the original PDF, a SHA-256 fingerprint of the exact version signed, the consent text shown, timestamps and device evidence.
Sign-in, invitation and password reset flows are handled by the PHI HR application at app.phihr.co.uk. Single sign-on and multi-factor authentication are planned, not available today.
Product imagery on this website uses sanitised demonstration data from a synthetic tenant. No customer records are ever shown.
If you believe you have found a vulnerability or have a question about how your data is handled, contact us directly and we will respond as quickly as we can.
security@phihr.co.ukThis page describes current product controls. It is not a certification statement. PHI HR does not currently publish ISO 27001, Cyber Essentials or SOC 2 certification, an uptime SLA, penetration test results, or backup and disaster recovery commitments — if your procurement process requires any of those, please ask us directly.