From the time clock to the payslip — one straight run +84 789 723 672 Thanhnp87@Gmail.com
Scarlet Sails HRM logo Scarlet SailsHRM Platform
Home/Data security
Data security

HR and payroll data should be controlled from day one

Scarlet Sails HRM handles sensitive company data: employee files, ID-card information, bank accounts, attendance records, payroll formulas and payslips. The first question is not whether the UI looks good; it is where the data lives and who can view or change it.

Ownership

Your company chooses where the data lives

The system does not force payroll data into a shared third-party cloud. Depending on internal policy, it can run inside your company or on a private VPS.

Company server

  • Application and database stay inside the internal network
  • Works when payroll data must not leave the company
  • Your IT team controls backup, firewall rules and administrator access

Private VPS

  • One server for multiple sites and mobile self-service access
  • On-site agents sync attendance logs over an encrypted channel
  • Useful when staff need ESS access without exposing the internal network
Access control

Control layers built into the system

Sign-in and sessions

Time-limited tokens, refresh handling, throttled failed sign-ins and session history are part of the platform.

Company access

A user can only enter companies they are assigned to, keeping group-company data from bleeding across units.

Department scope

Access can be limited to a department tree, direct reports, or only the employee's own record.

Sensitive fields

Payroll, bank accounts, ID data and personal information are controlled by role and server-side data scope.

Audit logs

Important changes can be traced back to who changed what, when, and what the previous value was.

Period locking

Closed attendance and payroll periods can be locked to reduce accidental edits after figures are used for payment.

Approval chains

Leave, overtime and other controlled actions can follow multi-level approval by employee or department scope.

Backup planning

The backup plan depends on the deployment model. With on-premise hosting, internal IT can fully own the schedule.

Sensitive data

Not every field should be treated the same

In HRM, view permission and edit permission must be separated. A line manager may need team attendance, but not every salary line or identity document.

Data group Risk when access is too broad Control to enable
Salary and allowances Exposure of income, formulas and personal deductions Role permissions, data scope and payroll period locking
ID cards, address, bank accounts Exposure of personal data, document images and payment details Limit to authorised HR roles and control uploads/downloads
Attendance logs and edits Wrong clock-in/out edits without traceability before payroll close Before/after audit trail, approval flow and anomaly reports
Accounts and permissions Over-granted access or former staff accounts staying active Periodic user review, account lockout and sign-in history
Plain answers

Questions worth asking before contract stage

Does Scarlet Sails claim ISO 27001 or SOC 2 certification?

Not on this website, because there is no public proof to publish. If procurement requires a formal certificate, raise it at the start so both sides can decide the right path.

Is two-factor authentication live today?

No. OTP/MFA screens have a design direction, but it should not be sold as a production feature yet. If 2FA is mandatory, it must be included in the implementation scope.

Who owns backup?

It depends on deployment. With a company server, internal IT owns the main backup schedule; the Scarlet Sails team can help configure checks, recovery tests and file-upload backup scope.

Can managers be limited to their own department?

Yes. The platform supports data scope by department tree, direct reports or the employee's own record, applied server-side rather than only hidden in the UI.

Bring your security requirements into the demo

Send the IT policy, data-scope rules and user groups ahead of time. The demo can then follow the way your company actually wants to control access.

Zalo