Encrypted salary, national ID and IBAN; a default-deny permission model; an audit log; attendance without biometrics, and now two-factor authentication (2FA).
The portal was designed around data protection: sensitive fields never reach the screen of a user without permission; they are removed from the query.
Managers see their own branch of the org chart, no more and no less. Scope comes from the chart, not the role; when the chart changes, permissions change with it.
Even someone with database access cannot read these fields.
A screen not defined in the permission map opens for no one at all, not even the company administrator.
Managers see only their own team tree; with an empty scope they see no one.
Who changed what, and when, is on record.
Verification that works with Google or Microsoft Authenticator and doesn't depend on SMS or a mobile operator. Even if a password is stolen, there's no login without the code; the same code can't be used twice and attempts are limited. Recommended for HR and manager accounts; if a phone is lost, HR resets it in one click.
Payslip delivery is kept as an irreversible record with date, time and IP; logins, approvals, 2FA events and critical changes are written to the audit log. "Who, when, what?" always has an answer.
If you decide to leave, all your data is delivered in a single archive: a CSV per table, uploaded documents and a SHA-256 checksum for every file. It is written into our contract: delivery within 15 days, a 60-day objection period, then irreversible deletion with a KVKK destruction record. Data is never held hostage; any debt is a separate matter. Hosting is in Türkiye.
Integration keys work only within the chosen scope (e.g. write attendance only); the system stores a hash of the key, not the key itself, so even a leaked database backup can't be used to call the API. Salary, national ID and IBAN are never returned by any API endpoint; webhook deliveries are HMAC-signed.
Invite your IT or data protection lead to the demo too.