In transit and at rest
HTTPS and managed encrypted storage.
HollyHR checks the organisation and permission before serving a record, protects selected sensitive fields, and publishes the providers involved so you can check the service against your own requirements.
Every people-data operation is limited to the selected organisation in HollyHR's application layer.
Platform-admin workspace entry is MFA-gated, and selected sensitive System Admin and HR Admin actions ask for fresh proof. Approved organisation-wide read-only view-as can happen with customer approval; there is no blanket staff impersonation route.
Primary HR records are in EU (AWS eu-central-1); uploaded documents and database backup copies are in UK (eu-west-2). Product analytics use EU (PostHog Cloud EU, AWS eu-central-1), error reporting uses EU (Sentry Germany region), and the application runtime is listed as EU/USA.
Email, billing and support providers have their own locations and transfer terms.
HTTPS and managed encrypted storage.
An additional application-encryption layer.
Short-lived authorised attachment access.
HollyHR schedules a nightly PostgreSQL archive in versioned London storage and has restored a prior S3 dump into a disposable Neon branch.
Leaver offboarding archives access. Erasure and provider-side records need separate handling. An authorised System Admin can prepare an organisation export without opening a support ticket.

Scoped access, encrypted transport and storage, private documents, backups, export, incident procedures and public status.
HollyHR is not currently certified to ISO 27001, SOC 2 or Cyber Essentials, and does not currently publish an external penetration-test claim.
Public SLA, RPO and RTO targets are not currently published.
HollyHR combines server-side sessions, active-organisation membership checks, permission-aware services, application-scoped database queries, extra encryption for selected high-sensitivity values, private signed document access and audit records for sensitive actions.
Primary HR records and the application runtime are in the EU, while uploaded documents and HollyHR database backup copies are stored in AWS London. Supporting providers, including email, billing, support and human mailbox services, have their own regions and transfer terms, so HollyHR does not claim that all processing stays in the UK.
The customer controls its organisation data. HollyHR processes that data to provide the service under its Data Processing Agreement. Customers can prepare an organisation export without opening a support ticket, but some provider records and legal-retention evidence have separate handling boundaries.
Yes, but the policy is deliberately described by scope. Platform-admin workspace entry is MFA-gated. Selected sensitive System Admin and HR Admin actions require a fresh step-up, and tenant users may enrol a second factor. HollyHR does not yet claim universal MFA enforcement whenever every privileged tenant user signs in.
Not through blanket tenant impersonation. Support or security access is capability-gated, purpose-bound, time-limited and organisation-bound, and person-bound where applicable. Platform-admin workspace entry is MFA-gated; selected sensitive reveals and actions require fresh step-up. Approved organisation-wide read-only view-as can occur with customer approval, so HollyHR does not claim that staff can never see customer data.
HTTPS protects service traffic and the managed database and object-storage providers encrypt data at rest. HollyHR also applies authenticated application encryption to selected bank, tax or government identifier and compensation values.
HollyHR schedules a nightly PostgreSQL archive, checks the compressed archive and stores it in a versioned AWS S3 bucket in London. A prior S3 dump has been restored into a disposable Neon branch.
HollyHR has documented incident and personal-data-breach procedures, production health checks and a public status page. Affected customers would be contacted according to the contractual and legal circumstances.
No. HollyHR is not currently certified to ISO 27001, SOC 2 or Cyber Essentials, and it has not completed an external penetration test.
An authorised customer can prepare a structured organisation export with named CSV areas, eligible uploaded files and a manifest. Ordinary leaver offboarding archives access; it is not data erasure, and the person's records remain. Verified erasure removes or anonymises identifying live data, queues known document and avatar objects for deletion, and retains justified referential, audit, statutory and operational records. Provider-side records need separate handling, while backup copies age out rather than disappearing instantly.
No software makes an employer automatically compliant. HollyHR provides a DPA, sub-processor register, access controls, export, DSAR and erasure routes to support UK GDPR duties. The customer still decides lawful basis, notices, permissions, retention and how the service is used.
Holly uses an approved Claude model through Amazon Bedrock. The current route has request and response retention set to none, invocation logging unconfigured and commercial terms that prohibit training on customer content. A customer-selected agent connected through API or MCP remains subject to that provider's own retention, training, region and sub-processor terms.
See HollyHR with your own team, or bring us a security question first. You can start without a card or sales call.