ZaffreZaffre Axon
← All articles

HR Software Security Checklist: What to Demand From Vendors

Zaffre Tech · June 17, 2026

Your HR system holds the most sensitive records your organization keeps: national ID numbers, salaries, bank details, medical notes, performance reviews, and disciplinary history. When you evaluate an HR platform, security cannot be an afterthought buried on the last slide of a sales deck. It has to be a hard requirement you test, line by line, before a single employee record is uploaded. This checklist gives HR and IT leaders a concrete set of questions to put in front of every vendor, and shows where a modern platform like Zaffre Axon sets the bar.

1. How are passwords stored?

This is the fastest way to separate serious vendors from risky ones. If a vendor can email you your own password, retrieve it for you, or display it anywhere, walk away. Passwords should be hashed with a slow, salted algorithm such as bcrypt and never stored or shown in readable form. In Zaffre HRM, passwords are hashed with bcrypt and are never stored or viewable as plain text, even by administrators.

2. Is data encrypted in transit and at rest?

Ask two distinct questions, not one. Data in transit must be protected with TLS so nothing travels the network in the clear. Data at rest must be encrypted on disk and in backups so a stolen drive or leaked file is useless to an attacker. Zaffre Axon encrypts data in transit with TLS and at rest, and ships encrypted backups by default.

3. How granular is access control?

An HR clerk should not see executive salaries. A line manager should see their team and no one else. Demand role-based access control (RBAC) that is granular down to the field and record level, not a blunt admin-or-not switch. Zaffre HRM enforces granular RBAC so no employee can view another employee's credentials or restricted data, and view scopes can be limited to self, subordinates, or the whole organization.

4. Is there a complete audit trail?

If something changes, you need to know who changed it, when, and from where. A real audit trail is immutable and covers logins, record edits, exports, and permission changes. Without it, accountability is impossible and so is any meaningful breach investigation.

5. Can you restrict by IP, device, or location?

Sensitive HR functions should not be reachable from anywhere on earth by default. Look for IP, device, and geo restrictions so payroll and personnel data are only accessible from approved networks. Zaffre Axon supports IP, device, and geo restrictions out of the box.

6. What are your hosting and data-residency options?

Some organizations are comfortable with managed cloud. Others, for regulatory or policy reasons, must keep data inside their own walls. The right vendor offers a real choice. Zaffre Axon can run as managed cloud or fully self-hosted on your in-house database, restricted to your internal LAN or VPN, so data residency stays entirely under your control. Learn more on our security page.

7. How are tokens and sessions secured?

Session tokens are a common weak point. Ask whether tokens are cryptographically signed and how sessions expire. Zaffre Axon uses RS256-signed tokens so authentication cannot be silently forged.

8. Will it scale without cutting corners?

Security and performance are not opposites, but weak architecture forces trade-offs. Confirm the platform is built to scale. Zaffre Axon runs on a clustered API that scales to 1000+ employees with real-time updates and high uptime, so growth never becomes an excuse to weaken controls.

The questions to send every vendor

  • Are passwords hashed with bcrypt and never viewable?
  • Is data encrypted in transit (TLS) and at rest, including backups?
  • Is RBAC granular to the field and record level?
  • Is there an immutable, complete audit trail?
  • Can access be restricted by IP, device, and geography?
  • Can we self-host for data residency if required?
  • Are session tokens cryptographically signed?

Why one connected platform beats a patchwork

Every extra tool you bolt on is another login, another data copy, and another attack surface. Zaffre Axon runs HR, payroll, attendance, operations, finance, and secure communication on a single connected data layer, which means fewer exports, fewer integrations to harden, and one consistent security model across everything. That is a meaningful reduction in risk compared with stitching together separate point tools.

Use this checklist as a scorecard, not a formality. The vendor that answers every item with a confident, specific yes is the one that deserves your employees' data. Book a demo to see how Zaffre Axon meets each requirement in a live environment.