UBCC HRM Security Policy / Trust Overview
1. Our Approach to Security
Security is treated as a shared responsibility across engineering, IT, and operations, overseen by our Chief Information Security Officer (CISO). We follow a defense-in-depth approach: no single control is relied upon to protect Customer Data, and controls are reviewed at least annually or after any material change to the Platform or its infrastructure.
2. Certifications and Compliance Roadmap
UBCC HRM is working toward independent verification of its security program, targeting SOC 2 Type II and ISO/IEC 27001 by Q3 2028. UBCC HRM does not process payment card data directly; card transactions are handled by a third-party, PCI DSS-compliant payment processor. Current status and available reports can be requested through our Trust Center at https://trust.ubcc.com (to be published), subject to a mutual non-disclosure agreement, consistent with common industry practice among comparable payroll and HR platforms.
3. Encryption
Data is encrypted in transit using TLS 1.2 or higher for all connections to the Platform, and at rest using AES-256 encryption on the underlying storage, including both database records and uploaded documents. Encryption keys are managed through a dedicated key-management service with restricted access.
4. Access Controls
Customer Data is isolated across three nested tenant levels (payroll company, employer, and employee), and access rules are enforced in the data layer itself on every read and write, so they cannot be bypassed by a bug in application code. Evaluation is fail-closed: a rule that does not explicitly grant access returns nothing, and a request for a record the caller is not permitted to see returns as not found rather than revealing that the record exists. The caller’s active tenant is resolved and validated on the server on every request, so a modified client-side value cannot grant access to another tenant’s data. Access is further restricted at the level of individual fields: Social Security numbers and bank routing/account numbers are readable only by the Worker themselves, their employer’s administrators, and the payroll company, and are excluded from the underlying query — not merely filtered afterward — for any role not entitled to them; the same restriction applies to writes. Multi-factor authentication is required for internal administrative and production system access. Where a Customer invites a bookkeeper, accountant, or other professional as an Administrator under Section 2 of the Terms of Service, that Administrator is treated as an administrator of the Customer’s own tenant and is subject to the same tenant-isolation, fail-closed, and field-level restrictions described above — UBCC HRM does not grant an invited Administrator any broader access than the Customer’s own administrators have.
5. Audit Logging
Every create, update, and delete is recorded in a central audit log, written in the same database transaction as the change itself, so a change and its audit entry always succeed or fail together — a change can never be made without a corresponding log entry. Each entry captures who made the change, when, from which IP address, and the before-and-after values, and this history is available directly in the product for authorized users.
6. Document Handling
Uploaded documents (paystubs, tax forms, contracts, and other records) are never referenced by a raw storage URL within the Platform; each is addressed by an internal identifier and served through an authorization proxy that checks the requester’s access before streaming the file, so a guessed or leaked link cannot expose a document on its own. Uploads are written directly to private storage using a short-lived, server-issued grant scoped to a specific file, content type, and size limit, and uploaded content is checked against an allow-list of permitted file types, with executable files rejected outright.
7. Infrastructure and Availability
The Platform runs as a single web application on Vercel, with all infrastructure located in the United States. Structured HR and payroll records are stored in a Neon-hosted PostgreSQL database (AWS us-east-1); uploaded documents are stored in Vercel Blob storage; and payroll runs and the outbound email queue are handled by scheduled background jobs, coordinated through Upstash QStash, rather than running inline with user requests. We maintain regular, encrypted backups and test our restoration process on a periodic basis. Service status and any active incidents are published at https://status.ubcc.com (to be published).
8. Vulnerability Management and Testing
We conduct regular vulnerability scanning of our infrastructure and application code. Where penetration testing is performed, critical vulnerabilities are prioritized and remediated on an expedited timeline consistent with their severity.
9. Incident Response and Breach Notification
We maintain an incident response plan covering detection, containment, investigation, remediation, and communication. In the event of a security incident that compromises the confidentiality, integrity, or availability of Customer Data, we will notify affected employer-customers without undue delay and, in any event, within the timeframe required by applicable law and our contractual commitments (and no later than seventy-two (72) hours after we become aware of a confirmed incident affecting their data), and will provide information reasonably necessary for the customer to meet its own legal notification obligations.
10. Vendor and Subprocessor Risk Management
Third-party vendors and subprocessors with access to Customer Data are subject to a security and privacy review before onboarding and are bound by contractual confidentiality and security obligations; each is scoped to a specific technical function and none has broad access to the underlying database. The subprocessors in current use, and what each can access, are set out below; this table will also be kept current at https://ubcc.com/subprocessors.
| Service | Purpose | Data It Touches | Region |
|---|---|---|---|
| Vercel | Application hosting and document (blob) storage | Application traffic; uploaded documents | United States |
| Neon | Primary PostgreSQL database (system of record) | All HR and payroll records | United States (AWS us-east-1) |
| Upstash Redis | Cache | Short-lived cached values (record identifiers) | United States |
| Upstash QStash | Coordinates background jobs | Record identifiers and job instructions | United States |
| Pusher | Real-time in-product update signals | Change signals only; no personal data | United States |
| Resend | Outbound email and inbound document intake | Email addresses, message content, attachments | United States |
| Google Maps Platform | Address autocomplete and work-location maps | Addresses, work-location coordinates | United States (Google) |
| PostHog | Product-usage analytics | Internal user identifiers, usage events (no Social Security numbers or bank data) | United States |
11. Non-Production and Test Environments
Development and testing take place in environments separate from production. To mirror real-world conditions, these environments are currently seeded with data copied from production, which stays on the same U.S.-based infrastructure and under the same confidentiality obligations described in Section 12, and is never shared outside the team. UBCC HRM does not represent that data in non-production environments is masked, tokenized, or otherwise de-identified.
12. Personnel Security
Employees and contractors with access to production systems or Customer Data undergo background checks where legally permitted, sign confidentiality agreements, and complete security-awareness training upon hire and at least annually thereafter.
13. Business Continuity and Disaster Recovery
We maintain a business continuity and disaster recovery plan, including defined recovery time and recovery point objectives, and test that plan at least annually.
14. Reporting a Security Concern
If you believe you have found a security vulnerability affecting the Platform, please report it to info@ubcc.com. We ask that you not access or modify other customers’ data and give us a reasonable opportunity to investigate and remediate before public disclosure.
Version 1 · published 2026-10-07