Security & Compliance / Peopletree Group
SOC 2 Type II certified. Enterprise-grade data security, GDPR compliant processing, Azure cloud infrastructure, and 99.9% uptime SLA.
Serverless compute - application hosting
Relational data storage - AES-256 TDE encrypted
Assessment data storage - AES-256 encrypted
Cryptographic key management
Session and performance caching
Network isolation - private endpoints, no public IPs on databases
Inbound/outbound traffic control with defined port allowlists
Load balancer with WAF v2 - OWASP 3.2 ruleset
AI narrative generation - enterprise-grade AI model, no PII in prompts
Static asset delivery - global edge network
Infrastructure monitoring - 90-day+ log retention
Threat detection and vulnerability management
TLS 1.2 on all connections
AES-256 / FIPS 140-2 compliant
Transparent Data Encryption (TDE) on all SQL and MySQL instances
Azure Key Vault - dedicated per environment
Azure-managed SSL certificates with automated renewal
Auth0 - OIDC/JWT, SAML, ADFS, MFA enforced
Auth0, Microsoft Entra ID, ADFS/SAML - enterprise federation supported
Role-based access control (RBAC) at subscription and resource group level
JWT bearer tokens with defined expiration and rotation controls
VPN-gated management plane access - no public management ports exposed
Manager-approved access requests; revocation within 24 hours of termination
HRIS / Payroll
Any HRIS via API
Identity & SSO
OIDC-compatible providers
Data transfer
Secure SFTP (TLS 1.2, key-pair auth)
Azure ETL pipeline
Direct database integration on request
Analytics
Tableau (embedded analytics)
DataWiz custom dashboards
Export to Excel / CSV
Communication
SendGrid (transactional email - dedicated IP)
Tawk.to (live chat / ticketing)
Monitoring & logging
Sentry.io (exception tracing)
Log Analytics Workspace (90-day+ retention)
Microsoft Azure - EU-based data centre, GDPR-compliant region, with CDN edge nodes globally
Formal data classification policy - confidential, internal, and public tiers
Defined per customer contract; data purged on request within agreed SLA
Customer data logically isolated per tenant; no cross-tenant data access
Azure-managed geo-redundant backups with point-in-time restore
Azure OpenAI prompts contain only structured talent data - no personal or identifiable information included
Data processing agreements available; customer controls data classification and retention
Change & vulnerability management
- All changes reviewed, tested, and approved before deployment
- Continuous vulnerability scanning - critical patches within 24 hours
- Microsoft Defender for Cloud - real-time threat detection
Incident response
- Documented plan: identification, containment, remediation, and communication
- Notification to affected parties within agreed windows
- 90-day+ log retention via Azure Monitor and Log Analytics
Business continuity
- Documented BC/DR plan with defined resumption steps
- Geo-redundant storage with point-in-time restore
- Redundant infrastructure with load balancing on Azure
Personnel & vendor security
- Security awareness training and background checks for all employees
- Role-based access provisioning - revoked within 24 hours of termination
- All vendors assessed for security compliance before onboarding
Technical overview
Security &
Compliance
This page is designed for IT, security, and procurement teams evaluating the Peopletree Group platform. It covers cloud architecture, encryption standards, access controls, compliance certifications, and integration capabilities.
SOC 2 Type 2 Certified
Annual Penetration Testing
Security & Confidentiality
Audited by Laika Compliance LLC (AICPA)
No significant incidents recorded
Compliance posture
Security & Confidentiality - independently audited
Gray-box - all findings remediated
GDPR / POPIA
Data processing agreements available
Azure Security Centre
Continuous threat detection active
Cloud infrastructure
Platform architecture
The Peopletree platform runs entirely on Microsoft Azure in the Germany West Central region. All components are deployed within a private virtual network with no public-facing management ports.
Azure Germany West Central
Multi-zone redundancy
Geo-redundant with point-in-time restore
99.9% (Azure-backed)
Data protection
Encryption & access controls
Identity & access
Access management
Data governance
Data handling & residency
Connectivity
Integrations & interoperability
The Peopletree platform integrates with any data source via REST API, SFTP, or direct database connection. Named integrations below are pre-built and tested; custom integrations are scoped during implementation.
Certifications & audits
Peopletree Group undergoes independent third-party audits on an annual basis. Full reports are available to prospective customers and IT teams under NDA.
No significant incidents
Independent audit confirming controls for security and confidentiality were suitably designed and operated effectively throughout the audit period. Full report available under NDA.
Third-party assessment
Web applications & APIs
All remediated
Annual gray-box penetration test conducted by an independent security firm. All identified findings are remediated and validated before the report is closed. Executive summary available under NDA.
SOC 2 Type 2 - Security & Confidentiality
Audited by Laika Compliance LLC under AICPA Trust Services Criteria. The audit confirmed that Peopletree Group's controls for security and confidentiality were suitably designed and operated effectively throughout the audit period. The full report is available to prospective customers and business partners under NDA.
Operational controls
Security procedures
Full operational security procedure documentation - including incident response SLAs, change management policies, and BC/DR plans - is available in the
Client Portal
.