FairLens handles employer data that rivals the sensitivity of medical records — demographics, payroll, FMLA, ADA accommodations. Here's exactly how we protect it.
Every layer of our platform is designed to protect the sensitive HR data you entrust us with — from demographic data to ADA accommodation requests.
TLS 1.3 for all data in transit — no HTTP, ever. AES-256 encryption for all database storage. OAuth tokens and credentials get an extra layer of AES-256-GCM application-level encryption before storage.
Every customer lives in a logically isolated database partition. Queries are scoped by organization_id — cross-tenant access is architecturally impossible. Your data never mixes with other customers' data at the query level.
4 roles with granular permissions: Admin (full access), Investigator (assigned cases only), Reviewer (read-only), Employee (their own complaints). All access is logged. MFA is supported and recommended for Admin accounts.
Every action — case access, data export, user login — is logged with timestamp, user ID, and IP address. Audit logs are append-only and retained separately from case data. You can export audit history anytime.
We follow EEOC guidance (7 years minimum) by default. On cancellation, data is retained 90 days for export, then purged. Enterprise customers can request GDPR/CCPA-style deletions anytime via admin portal or support.
Uploaded files (payroll, demographics) are encrypted immediately upon upload and stored in encrypted storage. File validation runs before processing. Original files are never retained after processing — only structured, encrypted data.
ADA accommodation and FMLA data are flagged as sensitive categories. These require explicit access grants — not visible to general HR. Access triggers additional audit logging. Perfect for need-to-know compliance.
All data stored in Neon PostgreSQL on AWS us-east-1. No offshore data centers. No data leaves the United States. Backups are encrypted and retained for 30 days with point-in-time recovery available.
The data categories that require our highest protection level — and why FairLens treats them differently:
We're committed to meeting enterprise security standards. Here's where we are and where we're going.
Targeting Q3 2026
Active ✓
Active ✓
Targeting Q4 2026
AWS us-east-1 ✓
Immutable trail ✓
The questions IT and Legal teams ask us — with real answers.
All data is stored in Neon PostgreSQL on AWS us-east-1 (Northern Virginia). Data never leaves the United States. Backups are stored in the same region and are also encrypted.
If you have specific data residency requirements or need to discuss FedRAMP authorization, contact us for an Enterprise discussion.
By default: almost no one. Your data is isolated by organization ID in a multi-tenant database. The only people who could theoretically access it are:
We are implementing formal access review procedures as part of SOC 2 preparation (Q3 2026).
We maintain an incident response plan following NIST guidelines. In the event of a confirmed breach affecting customer data:
Our infrastructure providers (AWS, Render) maintain their own SOC 2 certifications and incident response procedures.
These are marked as Sensitive Categories in our system:
This helps you meet the "need-to-know" standard required for ADAinteractive process and FMLA records.
Exports: Full data export is available in JSON/CSV format from the admin dashboard — anytime, as often as you want. Export includes cases, evidence, audit logs, and user data.
Deletion:
No. Your case data is never used to train FairLens AI models or any third-party models. AI inference runs on:
Our privacy policy explicitly prohibits using customer data for model training.
The employee complaint portal is designed for maximum anonymity:
Important caveat: True anonymity depends on the employee's device and network. We recommend employees use personal devices. We cannot guarantee anonymity if the employee submits from a work device with monitoring software.
Currently, FairLens is not a HIPAA-covered entity. Our platform does not store "protected health information" (PHI) as defined by HIPAA — we store employment records and HR investigation data.
If your organization requires HIPAA compliance for specific use cases, contact us to discuss Enterprise arrangements.
Download our Trust Package — a single PDF with everything your IT, Legal, and Security teams need to approve FairLens.
A self-service download containing our security questionnaire responses, architecture overview, data processing agreement template, and SOC 2 roadmap. Everything you need for vendor review — no waiting for sales.
Security is complex, and we know you might have questions we haven't answered here. Our engineering team is available to work directly with your IT and Security teams.