From the time clock to the payslip — one straight run +84 789 723 672 Thanhnp87@Gmail.com
Scarlet Sails HRM logo Scarlet SailsHRM Platform
Home/Deployment
Deployment

Your payroll data stays where you decide

Nothing forces your payroll data onto a third-party cloud. Install on a server inside the company or on a VPS you control — either way, the database is yours.

Step 1 — choose where it lives

Two deployment models

On-premise — your own server

For when payroll data must not leave the building.

  • Application and database stay inside the internal network
  • No internet needed for daily attendance and payroll
  • Your IT team controls backup and recovery
  • A separate channel is required if staff should use the mobile app from outside

Private VPS

For multiple sites and access from anywhere.

  • One server serving every branch and the mobile apps
  • Agents at each plant push data over an encrypted connection
  • The server remains owned and administered by your company
  • No hardware or server room investment

These combine. The most common setup is the server on a VPS with a small agent inside each plant network. Time clocks never need to be exposed to the internet — only the agent reaches outward.

Step 2 — prepare the infrastructure

Technical requirements

A list your IT team can review and sign off before anything else happens.

ComponentRequirement
Application serverLinux or Windows. The application is built on .NET 10 and normally sits behind nginx for TLS termination and proxying.
DatabaseMicrosoft SQL Server or PostgreSQL. Pick whichever your organisation already runs — no new licence is forced on you.
User interfaceRuns in the browser. Nothing to install on individual workstations. Two web front-ends share one data server.
MobileNative Android and iOS apps for employees, plus a mobile web version usable straight from the phone browser with no install.
Attendance agentOne always-on Windows machine per site, on the same network as the time clocks. The agent installs as a service and starts with the machine. Modest hardware is fine.
NetworkingThe agent only makes outbound calls. No inbound ports into the plant network, and no time clock exposed to the internet.
Time clocksZKTeco and Ronald Jack fully supported. Logs can also be read from the database of existing attendance software. Some other brands need additional integration — see the features page.
EmailA company sending account is required for payslip delivery, training invitations and automated reminders.
Step 3 — go live

Rollout process

Discovery

We capture headcount, org structure, shift catalogue, pay policy, the device inventory and the state of existing data. The output is a plan with dates specific to your operation.

Installation

Application server and database are provisioned, domain and certificates configured. Later version upgrades run a health check and roll back automatically if the new build fails to start.

Load master data

Departments, positions, shifts, attendance symbols, employee records, cards, base salaries and current allowances. Most of it comes from Excel; where data sits in an old database we read it directly and match on employee code.

Connect the time clocks

Install the agent at each site, register devices, test connections, then sync a trial period and reconcile the punch count against the raw data on the device.

Build the payroll formulas

Your pay policy becomes a formula set in the system. We then run at least one period in parallel with your existing method and reconcile employee by employee.

Training and handover

HR staff are trained, permissions mapped to real roles, and employee self-service switched on when you are ready. The user guide lives inside the system and is editable.

Data protection

What is controlled out of the box

Access

  • Login issues an expiring token with a refresh mechanism
  • Failed login attempts rate-limited per minute
  • Active sessions and login history tracked
  • Users reach only the companies they are granted

Data scope

  • Limit to a department tree, direct reports, or self only
  • Mask salary, bank details and identity documents by role
  • Enforced server-side, not merely hidden in the interface

Audit trail

  • Field-level change log
  • Timesheet edits store a before and after snapshot
  • Attendance and payroll periods lock after closing
  • System error log readable from the interface

One point stated plainly. Two-factor authentication via authenticator app or OTP currently exists only as an interface draft, not working functionality. If 2FA is mandatory for your organisation from day one, raise it during discovery so it goes into the plan with a date — rather than being discovered after signing.

Send this page to your IT team

We are happy to work directly with your IT department to confirm feasibility before contract discussions begin.

Zalo