Security
Security built for sensitive workforce records
LicenceGuard holds the records UK employers are inspected on: right to work, DBS, pay and personal details. It is built with security controls aligned to modern SaaS security practices, including controls commonly associated with SOC 1 and SOC 2 frameworks.
- Card required
- Cancel during your trial
- No VAT currently charged
Overview
How LicenceGuard protects your data
Authentication and sessions
Session tokens are kept in secure, HTTP-only cookies and never exposed to browser scripts. Access tokens are short-lived, and repeated failed logins lock the account temporarily.
Permissions on every request
Every action is checked on the server against the user’s role, individual permissions and scope. Hiding a button is never the only control.
Organisation isolation
Each organisation’s data is separated by default on every database query. Only authorised platform staff can work across organisations.
Encrypted documents
Every uploaded file is individually encrypted and stored by a separate document service. Files are only reachable through download links that expire within minutes.
Audit and history
Security events, including denied access attempts, are logged with time, user and IP address. Records are never hard-deleted and every change is kept in history.
Privacy tooling
Data export for individuals and whole organisations, automated erasure and anonymisation, and configurable retention.

Authentication
Authentication and session controls
- Passwords are hashed with Argon2id and never returned by the application
- Session tokens live in secure, HTTP-only cookies, out of reach of browser scripts
- Short-lived access tokens, with refresh tokens stored hashed and rotated on use
- One active session per user; reuse of an old token ends the session
- Accounts lock for a period after repeated failed logins
- Rate limiting on sign-in and public endpoints
Permissions
Permissions and data scoping
Access is decided on the server for every request, never by role name alone.
- Built-in roles for organisation admins, HR managers, HR executives, accountants, managers and employees
- Custom roles start with no permissions; access is granted deliberately
- Each role assignment is scoped to the whole organisation, a department, a manager’s reporting team or the individual
- Single permissions can be granted to, or removed from, one person as an exception
- Reports containing personal data are hidden from users without the right permission
- Payroll release is restricted to the organisation admin; money actions cannot be set up to skip a person

Documents
Document protection
- Each file is encrypted individually (AES-256-GCM envelope encryption)
- Files are stored by a separate document service, apart from the main application
- No permanent file links: uploads and downloads use signed links that expire within minutes
- Confidential document types can be hidden from employees
- Stored credentials for integrations and email are encrypted at rest
Audit and history
Audit trail and record history
- Logins, failed logins and denied access attempts are logged with time, user, IP address and browser
- Business records are soft-deleted, never silently removed
- Every change to a record is captured in history automatically
- Compliance actions such as checks, verifications and acknowledgements carry who and when
Privacy
Privacy, retention and UK GDPR
LicenceGuard is built to support UK GDPR compliance.
- Export the personal data held about an individual
- Automated erasure and anonymisation
- Whole-organisation data export, with credentials removed
- Configurable retention periods
- Hosting in the UK (AWS London region) for application data
Responsible wording
We describe our controls as aligned to modern SaaS security practices, including controls commonly associated with SOC 1 and SOC 2 frameworks. LicenceGuard is not SOC 2 or ISO 27001 certified, and we do not display certification badges we have not earned.
You remain the controller of your employees’ data; LicenceGuard processes it on your behalf under our data processing terms.
Security or privacy question?
Email [email protected] with your question, or to report a potential security issue. Please include enough detail for us to investigate, and do not access data that is not yours.
Get started
Put sensitive workforce records somewhere built for them.
Start your 14-day free trial, or book a demo to talk through security with the team.
- Card required
- Cancel during your trial
- No VAT currently charged