🔒 Enterprise Data Security

Your Most Sensitive Data.
Our Highest Priority.

FairLens handles employer data that rivals the sensitivity of medical records — demographics, payroll, FMLA, ADA accommodations. Here's exactly how we protect it.

See How We Protect You → Download Trust Package

Built for the Most Sensitive Employment Data

Every layer of our platform is designed to protect the sensitive HR data you entrust us with — from demographic data to ADA accommodation requests.

🔐

Encryption at Rest & In Transit

TLS 1.3 for all data in transit — no HTTP, ever. AES-256 encryption for all database storage. OAuth tokens and credentials get an extra layer of AES-256-GCM application-level encryption before storage.

🛡️

Data Isolation by Organization

Every customer lives in a logically isolated database partition. Queries are scoped by organization_id — cross-tenant access is architecturally impossible. Your data never mixes with other customers' data at the query level.

👥

Role-Based Access Control

4 roles with granular permissions: Admin (full access), Investigator (assigned cases only), Reviewer (read-only), Employee (their own complaints). All access is logged. MFA is supported and recommended for Admin accounts.

📊

Immutable Audit Trail

Every action — case access, data export, user login — is logged with timestamp, user ID, and IP address. Audit logs are append-only and retained separately from case data. You can export audit history anytime.

🗑️

Data Retention & Deletion

We follow EEOC guidance (7 years minimum) by default. On cancellation, data is retained 90 days for export, then purged. Enterprise customers can request GDPR/CCPA-style deletions anytime via admin portal or support.

📁

Secure Data Import

Uploaded files (payroll, demographics) are encrypted immediately upon upload and stored in encrypted storage. File validation runs before processing. Original files are never retained after processing — only structured, encrypted data.

⚠️

Sensitive Data Extra Protection

ADA accommodation and FMLA data are flagged as sensitive categories. These require explicit access grants — not visible to general HR. Access triggers additional audit logging. Perfect for need-to-know compliance.

🏢

US-Based Infrastructure

All data stored in Neon PostgreSQL on AWS us-east-1. No offshore data centers. No data leaves the United States. Backups are encrypted and retained for 30 days with point-in-time recovery available.

💡 What's Sensitive Data?

The data categories that require our highest protection level — and why FairLens treats them differently:

  • Demographics — Race, gender, age, disability status for diversity reporting
  • Payroll data — Compensation, pay equity analysis
  • Time clock entries — Work history, attendance patterns
  • FMLA records — Medical leave requests and documentation
  • ADA accommodations — Disability-related requests andInteractive process records

Every Byte Encrypted, Every Access Logged

📤
Your Employee Data
Payroll, demographics, HR records
🔒
TLS 1.3 Transfer
Encrypted in transit
🗄️
AES-256 Storage
Encrypted at rest
Access Control
RBAC + audit logging

Certifications & Standards

We're committed to meeting enterprise security standards. Here's where we are and where we're going.

🛡️

SOC 2 Type I

Targeting Q3 2026

🔐

AES-256 Encryption

Active ✓

🌐

TLS 1.3

Active ✓

📋

SOC 2 Type II

Targeting Q4 2026

🇺🇸

US-Only Hosting

AWS us-east-1 ✓

📊

Audit Logging

Immutable trail ✓

Answers to Common Security Questions

The questions IT and Legal teams ask us — with real answers.

Where is data physically stored? Can it leave the US?

All data is stored in Neon PostgreSQL on AWS us-east-1 (Northern Virginia). Data never leaves the United States. Backups are stored in the same region and are also encrypted.

If you have specific data residency requirements or need to discuss FedRAMP authorization, contact us for an Enterprise discussion.

Who at FairLens can access our data?

By default: almost no one. Your data is isolated by organization ID in a multi-tenant database. The only people who could theoretically access it are:

  • Engineering support — Only for explicit support requests you initiate. Every access is logged to the audit trail.
  • Database infrastructure — Our cloud provider (Render/Neon) has operational access but cannot read your application data without compromising the entire platform.

We are implementing formal access review procedures as part of SOC 2 preparation (Q3 2026).

What happens in a data breach?

We maintain an incident response plan following NIST guidelines. In the event of a confirmed breach affecting customer data:

  • 72 hours — Affected customers are notified (per GDPR-equivalent standards)
  • Notification includes: nature of breach, data affected, response steps, recommended customer actions
  • 30 days — Root cause analysis and remediation summary provided

Our infrastructure providers (AWS, Render) maintain their own SOC 2 certifications and incident response procedures.

How do you handle FMLA and ADA data differently?

These are marked as Sensitive Categories in our system:

  • Not visible in default HR dashboard views — requires explicit "view sensitive" permission
  • Extra audit logging on every access (who viewed, when, from where)
  • Separate from general case data in the data model
  • Export restrictions — cannot be exported in bulk with other data

This helps you meet the "need-to-know" standard required for ADAinteractive process and FMLA records.

Can we export all our data? What about deletion?

Exports: Full data export is available in JSON/CSV format from the admin dashboard — anytime, as often as you want. Export includes cases, evidence, audit logs, and user data.

Deletion:

  • On cancellation: Data retained 90 days for export, then purged. Backup deletion follows 30-day retention schedule.
  • Per-record deletion: Enterprise customers can request deletion of specific records (e.g., "delete all data for employee X") for GDPR/CCPA compliance. Confirmed in writing within 30 days.
Do you use our data to train AI models?

No. Your case data is never used to train FairLens AI models or any third-party models. AI inference runs on:

  • Anthropic Claude — Case data is processed server-side, never stored by Anthropic, never used for training
  • Your own dedicated inference — No shared model between customers that could leak data

Our privacy policy explicitly prohibits using customer data for model training.

What about employee complaint data? Is it truly anonymous?

The employee complaint portal is designed for maximum anonymity:

  • No login required — employees submit without creating an account
  • No browser fingerprinting, no IP geolocation logging
  • Anonymous until employee chooses to identify themselves

Important caveat: True anonymity depends on the employee's device and network. We recommend employees use personal devices. We cannot guarantee anonymity if the employee submits from a work device with monitoring software.

Do you have a BAA (Business Associate Agreement) for HIPAA?

Currently, FairLens is not a HIPAA-covered entity. Our platform does not store "protected health information" (PHI) as defined by HIPAA — we store employment records and HR investigation data.

If your organization requires HIPAA compliance for specific use cases, contact us to discuss Enterprise arrangements.


Ready for Procurement Review?

Download our Trust Package — a single PDF with everything your IT, Legal, and Security teams need to approve FairLens.

📦 Trust Package

A self-service download containing our security questionnaire responses, architecture overview, data processing agreement template, and SOC 2 roadmap. Everything you need for vendor review — no waiting for sales.

📋
Security Questionnaire
Completed SIG, CAIQ, and custom questions
🏗️
Architecture Overview
Data flow diagrams, infrastructure details
📄
DPA Template
Data Processing Agreement for GDPR/CCPA
🛡️
SOC 2 Roadmap
Certification timeline and controls status

Questions? Let's Talk.

Security is complex, and we know you might have questions we haven't answered here. Our engineering team is available to work directly with your IT and Security teams.