Security

Employee data deserves careful handling

PHI HR holds sensitive people data. These are the controls in place today — described plainly, with no claims we cannot evidence.

Role-based permissions

Company Admin, HR Admin, manager and employee roles determine exactly what each person can see and do.

Company data isolation

Every table is company-scoped and membership-gated with row-level security enabled, so a user can only ever reach records belonging to a company they are a member of.

Employee data stored in the UK

Your employee data is stored in the United Kingdom, in AWS London. The web application itself is served over a global edge network, so we describe PHI HR as having UK data storage rather than claiming the whole service runs only in the UK.

Delegation without exposure

Delegated administrators, such as a Contracts Officer, are restricted at database level and provably cannot reach bank details, identity documents or pay data.

Controlled document access

Documents are stored securely and released only to users whose role permits access. Deletion is request-and-approve, and replacements retain the original.

Audit history

Company-level and per-domain audit events are recorded across contracts, leave, documents and training, supporting review and accountability.

Signing evidence

Signed contracts retain the original PDF, a SHA-256 fingerprint of the exact version signed, the consent text shown, timestamps and device evidence.

Authentication

Sign-in, invitation and password reset flows are handled by the PHI HR application at app.phihr.co.uk. Single sign-on and multi-factor authentication are planned, not available today.

Demonstration data only

Product imagery on this website uses sanitised demonstration data from a synthetic tenant. No customer records are ever shown.

Reporting a security concern

If you believe you have found a vulnerability or have a question about how your data is handled, contact us directly and we will respond as quickly as we can.

security@phihr.co.uk

This page describes current product controls. It is not a certification statement. PHI HR does not currently publish ISO 27001, Cyber Essentials or SOC 2 certification, an uptime SLA, penetration test results, or backup and disaster recovery commitments — if your procurement process requires any of those, please ask us directly.