18:30Legal
Security
Effective: 1 September 2026
Last updated: 1 September 2026
StaffVertex holds hours worked, pay rates, and in many organizations screenshots of the working day. This page describes how we protect it, and is honest about what we have not built yet.
- All traffic encrypted with current TLS, with strict transport security enforced.
- Data encrypted at rest by our database and file storage providers.
- Passwords stored only as one-way hashes, never recoverable.
- Every request checked against the requester's permissions before data is returned.
- Organizations kept separate, so a request can only ever reach its own organization's data.
- Sensitive administrative actions written to an audit log.
- Screenshot uploads go straight to storage using short-lived, single-purpose links.
- Rate limiting and automated-abuse protection on sign-in and other sensitive endpoints.
- Browser protections set at the edge, including a content security policy.
- Staff access limited to those who need it to run and support the service.
1. Encryption
In transit. Everything between your browser or desktop app and our servers travels over an encrypted connection using current TLS. We instruct browsers never to connect to us without it.
At rest. Our database and our file storage encrypt what they hold on disk. Screenshots are uploaded directly to storage using links that are valid for a single upload and expire quickly, so images never pass through an intermediate service.
On your own computer. The desktop app keeps its local database encrypted, with the key held in your operating system's keychain rather than in a file beside it.
2. Accounts and Passwords
- Passwords are stored only as one-way hashes. Nobody at StaffVertex can see or recover your password, and neither can anyone who obtained a copy of our database.
- We keep a history of your previous password hashes so that you cannot reuse a password you have already had.
- Password reset and email verification links are single-use and expire.
- Your sign-in sessions are recorded, including when and from which address they were created, so unfamiliar access can be spotted. Expired sessions are cleared automatically every day.
- Sign-up, sign-in and contact forms are protected against automated abuse.
3. Access Control
Between organizations. StaffVertex serves many organizations from one system. Every query is bound to the requester's organization, so one customer cannot reach another's data.
Within an organization. Permissions are checked on the server for every request, not just hidden in the interface. Administrators decide what each role can see and do, including who can view screenshots and pay information.
By us. Access to production systems is limited to the people who run and support the service. Sensitive administrative actions are recorded in an audit log. We access customer data only to operate the service, to fix a fault, or when you ask us to help with something.
4. The Desktop App
- Work is recorded to an encrypted local database first and synced afterwards, so a lost connection never costs you your hours.
- Your sign-in token lives in the operating system keychain (Windows Credential Manager or the macOS Keychain), not in a settings file.
- Screenshots can be blurred on your own machine before they are uploaded, if your organization enables that.
- The app updates itself, and older versions stop being supported over time so that security fixes actually reach everyone. You are warned inside the app before that happens.
- Activity measurement counts keyboard and mouse events. It does not capture what you type. There is no keylogger.
5. Infrastructure and Backups
- The application is hosted on managed infrastructure with network protection and denial-of-service mitigation at the edge.
- Our database runs on a managed service in the United States.
- Backups are taken continuously and kept for 8 days, so deleted data disappears from backups within 8 days of erasure.
- The providers we depend on are listed by name in our Privacy Policy.
6. What We Do Not Have
We would rather you heard this from us than discovered it during procurement. As of the date at the top of this page:
- We do not hold a SOC 2 report or an ISO 27001 certificate.
- We do not yet offer two-factor sign-in. It is something we intend to add.
- We have not had an independent penetration test, and we do not run a paid bug bounty.
- We do not publish an uptime guarantee or offer service credits.
- We do not currently delete screenshots automatically on a schedule. They remain until your organization removes them or closes the account. See how long we keep data.
If any of these matters to your organization, write to security@staffvertex.com and we will tell you honestly where we are.
7. Reporting a Vulnerability
If you have found a security problem in StaffVertex, please tell us. Email security@staffvertex.com with enough detail to reproduce it. We aim to acknowledge within two business days and to keep you updated until it is fixed.
Our promise to you
If you research in good faith and follow the rules below, we will not pursue legal action against you, and we will not ask anyone else to. We are glad to credit you publicly once a fix is out, if you would like that.
Please do
- Use only your own test accounts and your own data.
- Stop as soon as you have confirmed a problem, and go no further into anyone's data than you need to prove it.
- Give us reasonable time to fix it before telling anyone else.
Please do not
- Access, change or delete data belonging to another person or organization.
- Run denial-of-service tests, send bulk spam, or degrade the service for other people.
- Use social engineering against our staff, our customers or our providers.
- Attack the systems of the providers we rely on (report those problems to them instead).
We do not pay for reports today. That is a resourcing decision, not a judgement about the value of your work, and we say so plainly so nobody spends days on a submission expecting otherwise.
8. If Something Goes Wrong
If personal information is exposed or accessed without authority in a way that puts people at risk, we will notify affected organizations without undue delay and, where we can, within 72 hours of establishing what happened. We will tell you what occurred, what was involved, what it may mean, and what we are doing about it. Where the law requires, we will notify the relevant authority.
We will not stay quiet about an incident to protect our reputation.
9. Your Part
Most account compromises start outside the system we control. You can help:
- Use a long, unique password that you do not use on any other site. A password manager makes this easy.
- Never share your account with a colleague.
- Remove members promptly when they leave, and review who holds administrator rights.
- Grant the least access each person needs, particularly for screenshots and pay information.
- Tell us at once at security@staffvertex.com if you think an account has been reached by someone else.