PillarRise
Support Line0216 706 34 26
Digital HR  ›  Security & Data Protection
Digital HR · Security & KVKK

Protecting personal data is not a feature added later.

Encrypted salary, national ID and IBAN; a default-deny permission model; an audit log; attendance without biometrics, and now two-factor authentication (2FA).

Security & Data Protection

Protecting personal data is not a feature added later.

The portal was designed around data protection: sensitive fields never reach the screen of a user without permission; they are removed from the query.

Managers see their own branch of the org chart, no more and no less. Scope comes from the chart, not the role; when the chart changes, permissions change with it.

Salary, national ID and IBAN are stored encrypted

Even someone with database access cannot read these fields.

Default deny

A screen not defined in the permission map opens for no one at all, not even the company administrator.

Scope comes from the organisation

Managers see only their own team tree; with an empty scope they see no one.

Audit log

Who changed what, and when, is on record.

New

Two-factor authentication (2FA)

Verification that works with Google or Microsoft Authenticator and doesn't depend on SMS or a mobile operator. Even if a password is stolen, there's no login without the code; the same code can't be used twice and attempts are limited. Recommended for HR and manager accounts; if a phone is lost, HR resets it in one click.

New

Notification and audit trail

Payslip delivery is kept as an irreversible record with date, time and IP; logins, approvals, 2FA events and critical changes are written to the audit log. "Who, when, what?" always has an answer.

New

Data freedom: one-click export + destruction record

If you decide to leave, all your data is delivered in a single archive: a CSV per table, uploaded documents and a SHA-256 checksum for every file. It is written into our contract: delivery within 15 days, a 60-day objection period, then irreversible deletion with a KVKK destruction record. Data is never held hostage; any debt is a separate matter. Hosting is in Türkiye.

API security

Scoped keys, no stored secrets

Integration keys work only within the chosen scope (e.g. write attendance only); the system stores a hash of the key, not the key itself, so even a leaked database backup can't be used to call the API. Salary, national ID and IBAN are never returned by any API endpoint; webhook deliveries are HMAC-signed.

FAQ

Common questions

Where is our data kept, and can we take it with us if we leave?
Data is hosted in Türkiye. Fields such as salary, national ID and IBAN are stored encrypted. Reports and lists can be exported to Excel; at the end of the contract you can request a full dump of your data.

Ask our technical team your security questions.

Invite your IT or data protection lead to the demo too.

WhatsApp
PositiveSSL güvenli site