HRMLESS Trust Center
Data as of Sep 5, 2026, 11:09 PM UTC

Security Practices

HRMLESS protects customer data through layered controls across infrastructure, application, and operations. This summary complements our published policies (available under Documents in the Trust Center) and is updated alongside our SOC 2 Type II control set.

Encryption

  • All data encrypted at rest using AES-256 via managed PostgreSQL (Digital Ocean) and encrypted object storage
  • All data encrypted in transit using TLS 1.3 -- enforced at the Cloudflare edge and between internal services
  • Secrets managed via HashiCorp Vault in HA Raft configuration spanning two availability zones
  • Vault authenticates via OIDC (Entra ID) for humans and Kubernetes service accounts for workloads
  • No secrets stored in code, environment files, or version control

Access Controls

  • Microsoft Entra ID serves as the central identity provider for all internal access with MFA enforced
  • Customer-facing authentication managed via Keycloak with OpenID Connect and role-based access controls
  • Quarterly access reviews cover all personnel across all systems -- Entra ID, vendor platforms, Kubernetes RBAC, database access
  • Least-privilege principle applied -- no shared credentials, role-based permissions, API key rotation
  • Segregation of duties between CTO (infrastructure, security), Principal AI Engineer (code, application security), and CEO (business, vendor management)

Infrastructure

  • Self-managed RKE2 Kubernetes cluster on CloudStack infrastructure across west and central availability zones
  • RKE2 selected for CIS benchmark compliance and hardened security defaults
  • Node provisioning automated via Ansible playbooks for consistent, reproducible deployments
  • Cloudflare provides DNS, SSL certificate management, WAF, and geo-based load balancing
  • Container images scanned for vulnerabilities; non-root container execution enforced

Monitoring & Logging

  • Continuous infrastructure and application health monitoring
  • Centralized logging for audit trail and incident investigation
  • Vault audit logging for all secret access events
  • Entra ID sign-in logging for authentication events
  • Kubernetes audit logging for cluster operations

Incident Response

  • Documented incident response plan with severity-based classification (SEV-1 through SEV-4)
  • SEV-1 response target: 30-minute initial response with customer notification
  • SEV-2 response target: 2-hour initial response
  • Incident commander role (CTO) with defined escalation to CEO for customer communication
  • Post-incident review and documentation for all SEV-1 and SEV-2 incidents

Personnel Security

  • Annual security awareness training for all team members covering policy, threats, and role-specific responsibilities
  • Security policy acknowledgment required from all personnel
  • Role-specific security training: infrastructure security (CTO), application security (Principal AI Engineer), data handling and incident reporting (all staff)
  • Background checks conducted during hiring process

Vendor Security

  • All critical and high-criticality vendors evaluated for security posture before adoption
  • SOC 2 Type II reports collected and reviewed annually for critical vendors
  • Vendor incident response process defined -- vendor security incidents trigger HRMLESS IR process
  • Annual vendor review covers security posture, incident history, service performance, and data handling changes
  • Subprocessor list published and kept current