Access
- Login issues an expiring token with a refresh mechanism
- Failed login attempts rate-limited per minute
- Active sessions and login history tracked
- Users reach only the companies they are granted
Nothing forces your payroll data onto a third-party cloud. Install on a server inside the company or on a VPS you control — either way, the database is yours.
For when payroll data must not leave the building.
For multiple sites and access from anywhere.
These combine. The most common setup is the server on a VPS with a small agent inside each plant network. Time clocks never need to be exposed to the internet — only the agent reaches outward.
A list your IT team can review and sign off before anything else happens.
| Component | Requirement |
|---|---|
| Application server | Linux or Windows. The application is built on .NET 10 and normally sits behind nginx for TLS termination and proxying. |
| Database | Microsoft SQL Server or PostgreSQL. Pick whichever your organisation already runs — no new licence is forced on you. |
| User interface | Runs in the browser. Nothing to install on individual workstations. Two web front-ends share one data server. |
| Mobile | Native Android and iOS apps for employees, plus a mobile web version usable straight from the phone browser with no install. |
| Attendance agent | One always-on Windows machine per site, on the same network as the time clocks. The agent installs as a service and starts with the machine. Modest hardware is fine. |
| Networking | The agent only makes outbound calls. No inbound ports into the plant network, and no time clock exposed to the internet. |
| Time clocks | ZKTeco and Ronald Jack fully supported. Logs can also be read from the database of existing attendance software. Some other brands need additional integration — see the features page. |
| A company sending account is required for payslip delivery, training invitations and automated reminders. |
We capture headcount, org structure, shift catalogue, pay policy, the device inventory and the state of existing data. The output is a plan with dates specific to your operation.
Application server and database are provisioned, domain and certificates configured. Later version upgrades run a health check and roll back automatically if the new build fails to start.
Departments, positions, shifts, attendance symbols, employee records, cards, base salaries and current allowances. Most of it comes from Excel; where data sits in an old database we read it directly and match on employee code.
Install the agent at each site, register devices, test connections, then sync a trial period and reconcile the punch count against the raw data on the device.
Your pay policy becomes a formula set in the system. We then run at least one period in parallel with your existing method and reconcile employee by employee.
HR staff are trained, permissions mapped to real roles, and employee self-service switched on when you are ready. The user guide lives inside the system and is editable.
One point stated plainly. Two-factor authentication via authenticator app or OTP currently exists only as an interface draft, not working functionality. If 2FA is mandatory for your organisation from day one, raise it during discovery so it goes into the plan with a date — rather than being discovered after signing.
We are happy to work directly with your IT department to confirm feasibility before contract discussions begin.