Skip to content
Peerroll

Security and trust

Controls you can describe. No invented badges.

Peerroll handles employee records, time evidence, and documents. That is sensitive even when it is not PHI. Here is how we talk about encryption, access, backups, and HIPAA without pretending we already hold certifications we have not published.

What this page does not claim

We do not list SOC 2, ISO 27001, HITRUST, or HIPAA certification. If a later report exists, it will appear here with a date. Until then, treat any third-party “Peerroll is certified” line as false.

Encryption

Data in transit uses TLS. The product is designed to encrypt stored records at rest. We will publish cipher and key-handling detail to customers under NDA, not as a homepage badge.

Access controls

Role-based access for operators, managers, and employees. Sensitive fields are not on the default manager view. Shared passwords are a failure mode we refuse to design for.

Audit trail

Opens and edits on personnel files, punches, notes, documents, and e-sign packets should leave a record: who, when, and from where we can see it. That is how you answer counsel.

Backups

The operating plan is regular encrypted backups with a restore path you can ask us to demonstrate. Retention windows will be written into customer agreements, not guessed here.

HIPAA-minded posture

Some US employers store health-related notes, leave documentation, or clinic files next to the employee record. Peerroll is built for HIPAA-minded employers: minimize who can see it, encrypt it, log access. This site does not claim HIPAA certification, a completed security audit, or that we are a covered entity.

Business Associate Agreements

BAAs will be available when the product is generally available and we can stand behind the environment. Email hello@peerroll.com if your counsel needs that on the calendar.

Roles you can walk through

The day-to-day question is simple: who is allowed to see this? Operators run people ops. Managers approve work for their team. Employees punch, request leave, and finish their own tasks. Roles and access covers the product split. This page is the trust story around it.

  • Least privilege is the default. Extra access is granted.
  • HR-only notes never sit on the manager digest or team attention email.
  • A founder wearing two hats still has two roles — not one shared password.

Access

Who can see what

Least privilege
Product mock of role-based access for operators, managers, and employees.
  • Directory & job info

    Operator
    Edit
    Manager
    Team
    Employee
    Self
  • Time punches

    Operator
    All
    Manager
    Team
    Employee
    Own
  • PTO balances

    Operator
    All
    Manager
    Team
    Employee
    Own
  • HR-only notes

    Operator
    Yes
    Manager
    No
    Employee
    No
  • Compensation

    Operator
    Yes
    Manager
    No
    Employee
    Self*

What we expect to hold

You decide what you put in the file. We design as if some of it will be sensitive. We do not ask you to move a hospital chart into Peerroll.

Identity and job data

Names, contact details, site, manager, employment type, and status. This is the directory. Managers see what they need to run a team.

Time evidence

Punches, device, IP, and location when provided. Needed for attendance and wage-hour questions. Not a public feed.

Leave and documents

Balances, requests, e-sign packets, acknowledgements, and the document library on the e-file. Some files are routine. Some are not. Roles decide.

HR-only notes

Operator context that must not appear in a manager queue or an employee profile. Opening a note is an audit event.

Direct answers

Send this page to counsel before you send a roster.

Tell us your headcount and what you run today. We will write back from hello@peerroll.com when we can show you the product.