Security

Hermetis means sealed. Open to the right data. Closed to everything else.

HR and payroll data is among the most sensitive information a company holds. Hermetis is built on the assumption that protecting it is not a compliance checkbox – it is the foundation everything else rests on.

Security_Header Illustration
Companies that chose Hermetis
Lidl_Logo_Basis_115x115px_RGB 1
TMH LOGO primary 1
luminor 1
logo 1
kronus 1
Bosch_symbol_logo_black_red_LV 1
OUR POSITION

A system handling employment contracts, payslips, social security data, and tax filings across four countries should be held to the highest standard available.

NIS-2, DORA, ISO 27001. Hermetis holds all three, because the companies we work with require it.

Security_our position_illustration

Medium length section heading goes here

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla.

  • Build, approve, and process working time schedules
  • Register absences – time records update on approval
  • Register absences – time records update on approval
Placeholder Image
Infrastructure

EU data residency. Isolated by country. Encrypted throughout.

SOC 2 certified data centers within the European Union.

No data leaves EU jurisdiction at any point in the processing chain.

data residency

European Union · Belgium

All employee data processed and stored in SOC 2 certified EU data centres. Data does not leave EU jurisdiction at any layer.

Country-level isolation

Isolated at infrastructure level

Lithuanian, Latvian, Estonian, and Polish records are not co-mingled at any layer – network, database, or application.

encryption

TLS 1.3 in transit · AES-256 at rest

Cryptographic key management via encrypted vaults. All connections over HTTPS. No plaintext data at rest.

Availability and recovery

SLA-backed uptime · RTO 4h · RPO 24h

High-availability with automatic failover. 14 days daily encrypted backups + 7 days point-in-time recovery. Stricter terms on request.

Governance and controls

Security governed from the top – not delegated to a checklist.

Cybersecurity strategy is approved and enforced by executive management.

A fully operational ISMS is in place, with regular risk assessments, asset classification, and internal and external audits.

Access control

Every action is logged. Access is limited to what each role requires.

SSO or MFA required for all production and internal systems. RBAC enforces least-privilege at every layer. All administrative actions logged. Support access requires a customer ticket reference. No direct database or server access without formal approval.

development

Security reviewed at every stage of development.

Version-controlled source code with mandatory peer reviews. SAST, DAST, and SCA scanning in CI/CD. Isolated development, staging, and production environments. No personal data extracted outside customer environments. Releases via signed and audited deployment process only.

Penetration testing

Tested continuously. Issues feed back into the process.

Automated penetration testing runs continuously. Manual penetration testing is available. Findings feed back into the risk management framework. Customer security audits supported. OWASP TOP 10 reports maintained.

Personnel security

Everyone on the team is trained. Key roles are trained more.

Mandatory annual security awareness training for all staff. Specialised OWASP and secure coding training for developers. Risk and incident management training for leadership. Confidentiality agreements for all privileged roles. Formal onboarding and offboarding access procedures.

How a security evaluation works

We protect your information the same way we protect your employees' data.

Security starts before the contract. Here is exactly what to expect.

01

Initial demo

You see the product.

No sensitive data shared. No commitment required.

02

NDA signed

Mutual NDA before any technical or commercial discussion.

Your IT architecture and processes are protected.
So are ours.

03

Security documentation

ISO certificate, DPA template, and infrastructure overview

shared under NDA for your IT and procurement review.

04

Security Q&A

Your security team asks questions. We answer them.

Customer-led security audits supported on request.

05

DPA signed

Data Processing Agreement signed before any employee data enters the system.

everfield

Security backed by a European network – not a single team.

Hermetis is part of the Everfield portfolio, a group of mission-critical software companies operating across Europe. That relationship means something concrete for security: cross-portfolio CISO collaboration, shared best-of breed security tooling, and corporation-wide security standards that no standalone company of our size would independently sustain.

When the threat landscape changes – and it does, constantly. Hermetis does not face it alone. We face it as part of a network of security professionals working across multiple industries, multiple countries, and multiple  regulatory frameworks.

Frame 552 (2)
Third-party and supply chain

We hold our suppliers to the same standard we hold ourselves.

All vendors and subprocessors are categorised by criticality and subject to security due diligence before onboarding. All integrations operate on least-privilege access with encrypted communication.

If something is entered incorrectly, the full change history is visible to HR. Every update is effective-dated, nothing is overwritten, and nothing is lost. An employee who knows their data is correct, their payslip is accessible, and their requests are tracked does not need to wonder.

  • Security due diligence before any subprocessor is onboarded
  • Contractual DPAs, SLAs, security obligations, audit rights, data location, and exit plans
  • Ongoing monitoring of supplier cybersecurity posture
  • All integrations: least-privilege access, encrypted communication, TLS 1.3
Data Processor role

AGroup acts as your Data Processor. You remain in control.

Under GDPR, AGroup is classified as a Personal Data Processor – we process employee data strictly under documented Data Processing Agreements and your instructions as Data Controller.

Processing is lawful, purpose-limited, and subject to structured data minimisation and retention policies. We support your obligations for Data Subject rights – access, rectification, erasure, portability – through documented processes built into the platform.

  • Data Subject access rights
  • Right to rectification and erasure
  • Data portability
  • Documented DPA with AGroup
  • Breach notification in compliance with GDPR
  • Exit strategy – full data extraction and handover
HRM product link

The data Hermetis protects is managed in one place.

Employment contracts, salary records, social security data, absence history – all of it lives in the HR Management module, governed by the same access controls and audit trail as the rest of the platform.

  • Employment contracts and contract changes: effective-dated, approval-controlled
  • Full employee data with GDPR retention categories built in
  • Social security and tax parameters per country entity
  • Complete change history and audit trail – every edit logged
  • Role-based access: each person sees only what their role permits

Hermetic means sealed

Closed to the wrong data.

  • No data leaves EU jurisdiction on any integration path

  • Every connection authenticated and encrypted — TLS 1.3

  • Least-privilege access on every inbound and outbound flow

  • All integration activity logged and auditable

Hermetic means open to the right data

Fully open to the right ones.

  • Open RESTful API — any system that speaks REST can connect

  • SSO via OAuth 2.0 · SCIM 2.0 from Azure AD — standard

  • Workday, SAP, MS Dynamics, AXAPTA — all connected

  • Four integration patterns — one fits every IT landscape

If your organisation evaluates vendors on security before anything else – good. So do we.

Book a meeting. We will walk you through our security posture, sign an NDA, and share full documentation before any commercial decision is required.

FAQs

Didn't find your answer? Get in touch — we'll get back to you.

What certifications does Hermetis hold?

ISO/IEC 27001:2022 certified with a fully operational ISMS. Aligned to NIS-2 and DORA requirements as a third-party service provider. All data processing under GDPR as a documented Data Processor. Data centres are SOC 2 certified.

Where is employee data stored?

Employee data is stored in data centres located in the European Union. Each Legal Entity's data resides in its country jurisdiction; cross-region replication is not used for primary storage. Production environments are EU-only.

What is the uptime commitment?

System availability is committed contractually per customer agreement. Hermetis operates with redundant infrastructure, automatic failover for production services, and recovery procedures that are documented and tested.

Can we conduct our own security audit?

Yes. Customers can request a security review or audit as part of the engagement. Hermetis provides documentation including the ISMS overview, applicable certifications, the data processing agreement, and information about subprocessors. Specific audit terms (frequency, scope, on-site vs. document review) are agreed in the customer agreement.

How are integrations secured?

All integrations use encrypted transport (TLS) and authenticated endpoints. API access uses token-based authentication; identity provider integrations use OAuth 2.0. File-based exchanges with banks or authorities use the security mechanisms required by each receiving system. No plaintext credentials are stored.

What happens in the event of a security incident?

Hermetis maintains an incident response process aligned with applicable regulatory requirements, including GDPR breach notification timelines. Affected customers are notified per the timelines specified in the customer agreement. Incident handling includes containment, investigation, customer communication, and post-incident review with corrective measures.

How does Hermetis handle subprocessors?

Hermetis maintains a published list of subprocessors used in service delivery. The list is updated when changes occur; material changes are communicated to customers in advance. Each subprocessor is subject to a data processing agreement with security and confidentiality obligations equivalent to those Hermetis commits to customers.