Initial demo
You see the product.
No sensitive data shared. No commitment required.
HR and payroll data is among the most sensitive information a company holds. Hermetis is built on the assumption that protecting it is not a compliance checkbox – it is the foundation everything else rests on.
NIS-2, DORA, ISO 27001. Hermetis holds all three, because the companies we work with require it.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla.
SOC 2 certified data centers within the European Union.
No data leaves EU jurisdiction at any point in the processing chain.
data residency
All employee data processed and stored in SOC 2 certified EU data centres. Data does not leave EU jurisdiction at any layer.
Country-level isolation
Lithuanian, Latvian, Estonian, and Polish records are not co-mingled at any layer – network, database, or application.
encryption
Cryptographic key management via encrypted vaults. All connections over HTTPS. No plaintext data at rest.
Availability and recovery
High-availability with automatic failover. 14 days daily encrypted backups + 7 days point-in-time recovery. Stricter terms on request.
Cybersecurity strategy is approved and enforced by executive management.
A fully operational ISMS is in place, with regular risk assessments, asset classification, and internal and external audits.
Access control
SSO or MFA required for all production and internal systems. RBAC enforces least-privilege at every layer. All administrative actions logged. Support access requires a customer ticket reference. No direct database or server access without formal approval.
development
Version-controlled source code with mandatory peer reviews. SAST, DAST, and SCA scanning in CI/CD. Isolated development, staging, and production environments. No personal data extracted outside customer environments. Releases via signed and audited deployment process only.
Penetration testing
Automated penetration testing runs continuously. Manual penetration testing is available. Findings feed back into the risk management framework. Customer security audits supported. OWASP TOP 10 reports maintained.
Personnel security
Mandatory annual security awareness training for all staff. Specialised OWASP and secure coding training for developers. Risk and incident management training for leadership. Confidentiality agreements for all privileged roles. Formal onboarding and offboarding access procedures.
Security starts before the contract. Here is exactly what to expect.
Initial demo
You see the product.
No sensitive data shared. No commitment required.
NDA signed
Mutual NDA before any technical or commercial discussion.
Your IT architecture and processes are protected. So are ours.
Security documentation
ISO certificate, DPA template, and infrastructure overview
shared under NDA for your IT and procurement review.
Security Q&A
Your security team asks questions. We answer them.
Customer-led security audits supported on request.
DPA signed
Data Processing Agreement signed before any employee data enters the system.
Hermetis is part of the Everfield portfolio, a group of mission-critical software companies operating across Europe. That relationship means something concrete for security: cross-portfolio CISO collaboration, shared best-of breed security tooling, and corporation-wide security standards that no standalone company of our size would independently sustain.
When the threat landscape changes – and it does, constantly. Hermetis does not face it alone. We face it as part of a network of security professionals working across multiple industries, multiple countries, and multiple regulatory frameworks.
All vendors and subprocessors are categorised by criticality and subject to security due diligence before onboarding. All integrations operate on least-privilege access with encrypted communication.
If something is entered incorrectly, the full change history is visible to HR. Every update is effective-dated, nothing is overwritten, and nothing is lost. An employee who knows their data is correct, their payslip is accessible, and their requests are tracked does not need to wonder.
Under GDPR, AGroup is classified as a Personal Data Processor – we process employee data strictly under documented Data Processing Agreements and your instructions as Data Controller.
Processing is lawful, purpose-limited, and subject to structured data minimisation and retention policies. We support your obligations for Data Subject rights – access, rectification, erasure, portability – through documented processes built into the platform.
Employment contracts, salary records, social security data, absence history – all of it lives in the HR Management module, governed by the same access controls and audit trail as the rest of the platform.
Hermetic means sealed
No data leaves EU jurisdiction on any integration path
Every connection authenticated and encrypted — TLS 1.3
Least-privilege access on every inbound and outbound flow
All integration activity logged and auditable
Hermetic means open to the right data
Open RESTful API — any system that speaks REST can connect
SSO via OAuth 2.0 · SCIM 2.0 from Azure AD — standard
Workday, SAP, MS Dynamics, AXAPTA — all connected
Four integration patterns — one fits every IT landscape
Book a meeting. We will walk you through our security posture, sign an NDA, and share full documentation before any commercial decision is required.
Didn't find your answer? Get in touch — we'll get back to you.
ISO/IEC 27001:2022 certified with a fully operational ISMS. Aligned to NIS-2 and DORA requirements as a third-party service provider. All data processing under GDPR as a documented Data Processor. Data centres are SOC 2 certified.
Employee data is stored in data centres located in the European Union. Each Legal Entity's data resides in its country jurisdiction; cross-region replication is not used for primary storage. Production environments are EU-only.
System availability is committed contractually per customer agreement. Hermetis operates with redundant infrastructure, automatic failover for production services, and recovery procedures that are documented and tested.
Yes. Customers can request a security review or audit as part of the engagement. Hermetis provides documentation including the ISMS overview, applicable certifications, the data processing agreement, and information about subprocessors. Specific audit terms (frequency, scope, on-site vs. document review) are agreed in the customer agreement.
All integrations use encrypted transport (TLS) and authenticated endpoints. API access uses token-based authentication; identity provider integrations use OAuth 2.0. File-based exchanges with banks or authorities use the security mechanisms required by each receiving system. No plaintext credentials are stored.
Hermetis maintains an incident response process aligned with applicable regulatory requirements, including GDPR breach notification timelines. Affected customers are notified per the timelines specified in the customer agreement. Incident handling includes containment, investigation, customer communication, and post-incident review with corrective measures.
Hermetis maintains a published list of subprocessors used in service delivery. The list is updated when changes occur; material changes are communicated to customers in advance. Each subprocessor is subject to a data processing agreement with security and confidentiality obligations equivalent to those Hermetis commits to customers.