Security & data protection
Parmetra holds some of the most sensitive HR data there is: salaries broken down by gender. This page explains exactly how that data is protected.
EU data residency
The application, database and error tracking run in EU regions: workforce data is stored in Frankfurt and never leaves the European Union. Authentication is handled by a specialist identity provider certified under the EU-U.S. Data Privacy Framework, which holds only account-holder identities: names and work emails, never salary data.
Encryption everywhere
All traffic is encrypted in transit and all data is encrypted at rest. Third-party credentials, such as HRIS API secrets, are additionally sealed with AES-256-GCM before they touch the database.
Strict tenant isolation
Every record is scoped to your organisation and every query filters on it. Role-based access separates system administrators from HR managers, enforced on the server.
Complete audit trail
Every change to employee data, reports and assessments is recorded with actor, action, timestamp and diff: the evidence trail regulators and works councils expect.
GDPR by design
Parmetra acts as your processor. Error tracking scrubs personal data before anything is sent, exports stay under your control, and an organisation's data is deleted in full when it leaves.
Payments handled by a certified processor
Subscription payments are processed by a PCI DSS Level 1 payment provider. Card details never reach our servers.
Running a vendor security review? We answer security questionnaires quickly. Ask through our contact form.
Found a vulnerability? Report it through our contact form and we will acknowledge your report within five working days. security.txt