PurelyHR Main Logo
Product
Overview Staff Time-Off Time-Clock Time-Sheet Warnings Performance Talent
Pricing
Sign Up Free Login ©PurelyHR by Ironflow Technologies Inc.
Customers
Nonprofit Technology Education Healthcare Professional Services Manufacturing Construction
About Resources
Help Center Module Fact Sheets Blog Customer Stories PurelyHR + You Contact Us
PurelyHR Main Logo
  • Product
    • Overview
    • Staff
    • Time-Off
    • Performance
    • Time-Clock
    • Time-Sheet
    • Warnings
    • Talent
    • Why PurelyHR?
  • Pricing
  • Customers
    • Nonprofit
    • Technology
    • Education
    • Healthcare
    • Professional Services
    • Manufacturing
    • Construction
  • About
  • Resources
    • Help Center
    • Module Fact Sheets
    • Blog
    • Customer Stories
    • PurelyHR + You
    • Contact Us
  • Login
  • Start free trial
  • Book a demo
Try it Free
  • Terms of Use +
  • Privacy Basics
  • Privacy Policy +
  • Cookies
  • Security
  • GDPR

Security


LAST UPDATED: MAY 24, 2018

This Security Statement applies to the products, services, websites and apps offered by Ironflow Technologies Inc., which are branded as “PurelyHR”, except where otherwise noted. We refer to those products, services, websites and apps collectively as the “Services” in this Statement. This Security Statement also forms part of the user agreements for PurelyHR customers.

PurelyHR values the trust that our customers place in us by letting us act as protectors of their data. We take our responsibility to protect and secure your information seriously and strive for complete transparency around our security practices detailed below. Our Privacy Policy also further details the ways we handle your data.

Physical Security and Compliance

PurelyHR’s information systems and infrastructure are hosted within secured, world-class, SOC 2 accredited data centers. Physical security controls at our data centers include 24x7 monitoring, cameras, visitor logs and entry requirements.

PurelyHR is compliant with the Payment Card Industry’s Data Security Standards (PCI DSS 3.2) and can therefore accept or process credit card information securely in accordance with these standards. PurelyHR re-certifies this compliance annually.

Access Control

Access to PurelyHR’s technology resources is only permitted through secure connectivity (e.g., VPN, SSH) and requires multi-factor authentication. Our production password policy requires complexity, expiration, and lockout and disallows reuse. PurelyHR grants access on an as-needed basis, reviews permissions quarterly, and revokes access within 12 hours of employee termination.

Security Policies

PurelyHR maintains and regularly reviews and updates its information security policies on an annual basis.

Personnel

PurelyHR conducts background screening at the time of hire (to the extent permitted or facilitated by applicable laws and countries). In addition, PurelyHR communicates its information security policies to all personnel, and requires new employees to sign employment agreements.

Vulnerability Management and Penetration Tests

PurelyHR maintains a documented vulnerability management program which includes periodic scans, identification, and remediation of security vulnerabilities on servers, workstations, network equipment, and applications. All networks, including test and production environments, are regularly scanned using trusted third party vendors. Critical patches are applied to servers on a priority basis and as appropriate for all other patches.

Encryption

We encrypt your data in transit using secure TLS cryptographic protocols. We also pseudo-anonymise all personal data at rest.

Development

Our development team employs secure coding techniques and best practices, focused around the OWASP Top Ten.

Development, testing, and production environments are separated. All changes are peer reviewed and logged for performance, audit, and forensic purposes prior to deployment into the production environment.

Asset Management

PurelyHR maintains an asset management policy which includes identification, classification, retention, and disposal of information and assets. Company-issued devices are equipped with up-to-date antivirus software. Only company-issued devices are permitted to access corporate and production networks.

Information Security Incident Management

PurelyHR maintains security incident response policies and procedures covering the initial response, investigation, customer notification (no less than as required by applicable law), public communication, and remediation. These policies are reviewed regularly.

Breach Notification

Despite best efforts, no method of transmission over the Internet and no method of electronic storage is perfectly secure. We cannot guarantee absolute security. However, if PurelyHR learns of a security breach, we will notify affected users without undue delay so that they can take appropriate protective steps. We are committed to keeping our customers fully informed of any matters relevant to the security of their account and to providing customers all information necessary for them to meet their own regulatory reporting obligations.

Business Continuity Management

PurelyHR’s databases are backed up on a rotating basis of full and incremental backups and verified regularly. Backups are stored within the production environment to preserve their confidentiality and integrity and are tested regularly to ensure availability.

Your Responsibilities

Keeping your data secure also requires that you maintain the security of your account by using sufficiently complicated passwords and storing them safely. You should also ensure that you have sufficient security on your own systems.

Product
  • Pricing
  • Overview
  • Staff
  • Time-Off
  • Warnings
  • Time-Clock
  • Time-Sheet
  • Performance
  • Talent
Free Tools
  • Out Of Office Generator
  • PTO Accrual Rate Calculator
  • PTO Calculator
  • Time-Card Calculator

Customers
  • Customer stories
  • Nonprofit
  • Technology
  • Education
  • Healthcare
  • Professional services
  • Manufacturing
  • Construction

Resources
  • Book a demo
  • Help center
  • Module fact sheets
  • Blog
  • Site Map
  • Login

Company
  • About
  • Contact us
  • Careers
  • Terms & Privacy
  • GDPR

© 2025 PurelyHR by Ironflow Technologies Inc.