Security
Access, data, and operational controls.
The following controls are described in the Dayzen V2 HRMS platform architecture. This page summarizes documented mechanisms — it is not a compliance certification claim.
What this page does — and does not — claim
This page describes first-party technical controls documented for Dayzen HRMS. It does not claim SOC 2, ISO 27001, GDPR certification, HIPAA, PCI, completed penetration tests, or insurance attestations unless those are separately verified and published here.
Documented controls
What the architecture describes today.
Authentication & sessions
JWT bearer authentication for API requests, with session expiry handling on unauthorized responses. Login, forgot-password, and tokenized reset flows are part of the HRMS app.
Permissions
Fine-grained module:action permission checks on the client and a server permission registry used to audit role integrity across modules.
Sensitive field encryption
AES-256-GCM encryption utilities for sensitive payload fields such as temporary passwords, using an organization metadata encryption key.
SSO building blocks
OIDC-oriented key generation and client registry utilities are present in the platform infrastructure for identity provider integration scenarios.
Content safety
HTML sanitization (DOMPurify) for rich-text job descriptions, SOP documents, and announcements before render.
Biometric data retention
Face-verification photos are subject to retention cron jobs that purge expired enrollment images according to organizational settings.
Need a deeper review? Bring SSO, retention, and access-control requirements to a demo or contact conversation. Also see About Dayzen for product identity and Contact for outreach channels. About Dayzen, Contact, and Privacy policy.
Discuss security requirements on a demo
Share your SSO, retention, and access-control needs with the Dayzen team.
