PeovixPeovix

Trust

Security & Trust

Built for organizations that need enterprise-grade data protection and governance, including MFA and optional biometric punch confirmation.

Role-aware controls · Audit-ready records · Device-bound biometrics

7-day free trial · No credit card required

Controls

SSO, MFA, audit, and privacy in one trust model

The same access and logging story as the platform module, without a product mockup standing in for a SOC report.

SSO via OIDC

Google, Okta, and Azure AD sign-in so workforce access follows your identity provider, not a second password store.

Optional MFA

TOTP multi-factor on admin and HR sessions. WebAuthn punch uses device-bound credentials, not a biometric database we store.

Audit log (Pro+)

Immutable trails for sensitive HR and admin actions. The audit log UI ships on Pro and Enterprise, not Starter.

Privacy requests

Role-aware access, tenant isolation, and export/delete workflows so privacy reviews do not require a spreadsheet hunt.

Trust matrix

What buyers typically ask first

SSO

Pro+

OIDC with Google, Okta, and Azure AD.

MFA

Pro+

Optional TOTP for privileged sessions.

Audit

Pro+

Immutable event log for sensitive actions.

Privacy

All plans

Subject access and deletion requests with role gates.

Security review path

Procurement and trust documentation

We support security questionnaires, architecture walkthroughs, and data-protection agreement requests during evaluation. Send questions through the contact form or security@peovix.com. What we describe here is encryption in transit (TLS 1.2+), encryption at rest (AES-256), SSO, optional MFA, audit logs, and tenant-scoped access. We do not publish SOC 2 or ISO badges.

Encryption at restSSO readyMFAAudit logsRBACOIDCTenant scoped

Architecture

How we protect workforce data

Encryption

TLS 1.2+ in transit and AES-256 at rest for platform data.

Access control

Four portals, RBAC, optional MFA (TOTP), SSO (OIDC), and least-privilege admin roles.

Tenant isolation

Organization-scoped data access so customer records stay separated.

Auditability

Immutable audit logs for sensitive HR and admin actions.

Operational reviews

Continuous monitoring, dependency patching, and regular security reviews.

Incident response

Documented incident triage and customer communication workflow.

MFA & biometrics

Optional TOTP multi-factor authentication and WebAuthn biometric punch confirmation for time clocks.

Responsible disclosure

Report suspected issues through security@peovix.com for coordinated response.

Trust & Security

Workforce data protection is built into our architecture, access model, and daily operations.

Encryption

Data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256.

Access control

Four role-based portals, least-privilege access controls, optional MFA (TOTP), and OIDC SSO reduce unnecessary data exposure.

Biometric punch

Optional WebAuthn confirmation (Face ID, fingerprint, or Windows Hello) for live time punch: device-bound credentials, not a biometric database we store.

Auditability

Security-sensitive and HR-sensitive actions are logged with immutable audit trails to support investigations and reviews.

Security operations

We run continuous monitoring, vulnerability management, and periodic access reviews for production systems.

Incident response

Our team follows a documented incident response process with severity triage, customer communication, and post-incident remediation.

Ready to run people ops in one place?

Start a 7-day trial or book a demo. Bring your regions and team size; we will map the right plan.

Prefer a quick walkthrough first? Explore the product in 3 minutes