Security & Compliance / Peopletree Group

SOC 2 Type II certified. Enterprise-grade data security, GDPR compliant processing, Azure cloud infrastructure, and 99.9% uptime SLA.

Serverless compute - application hosting

Relational data storage - AES-256 TDE encrypted

Assessment data storage - AES-256 encrypted

Cryptographic key management

Session and performance caching

Network isolation - private endpoints, no public IPs on databases

Inbound/outbound traffic control with defined port allowlists

Load balancer with WAF v2 - OWASP 3.2 ruleset

AI narrative generation - enterprise-grade AI model, no PII in prompts

Static asset delivery - global edge network

Infrastructure monitoring - 90-day+ log retention

Threat detection and vulnerability management

TLS 1.2 on all connections

AES-256 / FIPS 140-2 compliant

Transparent Data Encryption (TDE) on all SQL and MySQL instances

Azure Key Vault - dedicated per environment

Azure-managed SSL certificates with automated renewal

Auth0 - OIDC/JWT, SAML, ADFS, MFA enforced

Auth0, Microsoft Entra ID, ADFS/SAML - enterprise federation supported

Role-based access control (RBAC) at subscription and resource group level

JWT bearer tokens with defined expiration and rotation controls

VPN-gated management plane access - no public management ports exposed

Manager-approved access requests; revocation within 24 hours of termination

HRIS / Payroll

Any HRIS via API

Identity & SSO

OIDC-compatible providers

Data transfer

Secure SFTP (TLS 1.2, key-pair auth)

Azure ETL pipeline

Direct database integration on request

Analytics

Tableau (embedded analytics)

DataWiz custom dashboards

Export to Excel / CSV

Communication

SendGrid (transactional email - dedicated IP)

Tawk.to (live chat / ticketing)

Monitoring & logging

Sentry.io (exception tracing)

Log Analytics Workspace (90-day+ retention)

Microsoft Azure - EU-based data centre, GDPR-compliant region, with CDN edge nodes globally

Formal data classification policy - confidential, internal, and public tiers

Defined per customer contract; data purged on request within agreed SLA

Customer data logically isolated per tenant; no cross-tenant data access

Azure-managed geo-redundant backups with point-in-time restore

Azure OpenAI prompts contain only structured talent data - no personal or identifiable information included

Data processing agreements available; customer controls data classification and retention

Change & vulnerability management

  • All changes reviewed, tested, and approved before deployment
  • Continuous vulnerability scanning - critical patches within 24 hours
  • Microsoft Defender for Cloud - real-time threat detection

Incident response

  • Documented plan: identification, containment, remediation, and communication
  • Notification to affected parties within agreed windows
  • 90-day+ log retention via Azure Monitor and Log Analytics

Business continuity

  • Documented BC/DR plan with defined resumption steps
  • Geo-redundant storage with point-in-time restore
  • Redundant infrastructure with load balancing on Azure

Personnel & vendor security

  • Security awareness training and background checks for all employees
  • Role-based access provisioning - revoked within 24 hours of termination
  • All vendors assessed for security compliance before onboarding

Technical overview

Security &

Compliance

This page is designed for IT, security, and procurement teams evaluating the Peopletree Group platform. It covers cloud architecture, encryption standards, access controls, compliance certifications, and integration capabilities.

SOC 2 Type 2 Certified

Annual Penetration Testing

Security & Confidentiality

Audited by Laika Compliance LLC (AICPA)

No significant incidents recorded

Compliance posture

Security & Confidentiality - independently audited

Gray-box - all findings remediated

GDPR / POPIA

Data processing agreements available

Azure Security Centre

Continuous threat detection active

Cloud infrastructure

Platform architecture

The Peopletree platform runs entirely on Microsoft Azure in the Germany West Central region. All components are deployed within a private virtual network with no public-facing management ports.

Azure Germany West Central

Multi-zone redundancy

Geo-redundant with point-in-time restore

99.9% (Azure-backed)

Data protection

Encryption & access controls

Identity & access

Access management

Data governance

Data handling & residency

Connectivity

Integrations & interoperability

The Peopletree platform integrates with any data source via REST API, SFTP, or direct database connection. Named integrations below are pre-built and tested; custom integrations are scoped during implementation.

Certifications & audits

Peopletree Group undergoes independent third-party audits on an annual basis. Full reports are available to prospective customers and IT teams under NDA.

No significant incidents

Independent audit confirming controls for security and confidentiality were suitably designed and operated effectively throughout the audit period. Full report available under NDA.

Third-party assessment

Web applications & APIs

All remediated

Annual gray-box penetration test conducted by an independent security firm. All identified findings are remediated and validated before the report is closed. Executive summary available under NDA.

SOC 2 Type 2 - Security & Confidentiality

Audited by Laika Compliance LLC under AICPA Trust Services Criteria. The audit confirmed that Peopletree Group's controls for security and confidentiality were suitably designed and operated effectively throughout the audit period. The full report is available to prospective customers and business partners under NDA.

Operational controls

Security procedures

Full operational security procedure documentation - including incident response SLAs, change management policies, and BC/DR plans - is available in the

Client Portal

.