HomeFeaturesPricingFree toolsFor accountantsBlogAbout
Start free trial Book a demo Log in

Security

Enterprise-grade controls, without the enterprise complexity.

Audit trails, maker-checker approvals, role-based permissions, multi-factor authentication and encryption at rest and in transit, the controls your auditors and board expect, configured by HR rather than IT.

No card required · Free migration · Live in under a week

Enterprise security controls and data protection
Audit trail

Every create, edit, approve and delete logged with user, timestamp and before/after values.

Maker-checker

Sensitive changes require a second approver before they take effect.

Role-based access

Granular permissions by module, field and action, not just admin or not.

MFA & SSO

Multi-factor authentication and single sign-on for every user, every login.

Audit trail

Every change, accounted for.

Every create, edit, approve, reject and delete is logged automatically, who did it, when, from where, and what the values were before and after. The trail is tamper-evident and exportable for audit, with no way to silently alter or delete a record.

Filter by user, module, date range or action type and export to CSV or PDF for your auditors, your board, or your own peace of mind. Retention follows your data policy, not a vendor default.

Audit trail log with user, timestamp and change details

Maker-checker approvals

No single point of failure.

Salary changes, payroll runs, bulk edits, contract amendments and offboarding decisions can all be configured to require a second approver before they take effect. The maker proposes, the checker approves or rejects, and the audit trail captures both steps.

Approval routing is configurable by module and amount threshold: a small leave adjustment can auto-approve while a salary increase over a threshold routes to a second manager or finance. No more silent changes that surface at month-end.

Maker-checker approval workflow with pending and approved items

Role-based access control

Permissions down to the field.

Define roles by module, by action (view, create, edit, delete, approve) and by field, so a branch HR officer can see their own staff but not payroll figures, a line manager can approve leave but not change salaries, and finance can view payroll journals without editing employee records.

Permissions are inherited and overridable, so a regional structure can be set once and exceptions applied where needed. Every permission change is itself logged in the audit trail.

Role-based access control matrix with module and field-level permissions

Data encryption & residency

Encrypted everywhere it travels.

All data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Backups are encrypted and geographically replicated. Data residency options are available for organisations with specific jurisdictional requirements.

Personal data fields can be masked or restricted by role, so payslip details, ID numbers and medical notes are visible only to those explicitly permitted. The platform is ODPC-registered and aligned to Kenya's Data Protection Act and equivalent frameworks across our 36+ markets.

Security settings showing encryption, MFA and data residency options
The audit trail alone halved our compliance prep. Every question our auditors had, we could answer in two clicks.

Wahome Gitonga · MD, Flooring & Interiors

More ways to manage your team

The rest of the lifecycle.

The platform

Manage your growing team, all in one place.

Hire, onboard, manage, pay and develop your people on one system, with statutory compliance for 36+ countries built in rather than bolted on.

Questions

Frequently asked questions.

Can we customise roles beyond the defaults?

Yes. Every role is fully configurable by module, action and field. You can start from a default template and adjust, or build roles from scratch. Changes take effect immediately and are logged in the audit trail.

Is multi-factor authentication mandatory?

It is enabled by default for all accounts and cannot be disabled by individual users. Administrators can enforce additional policies such as hardware keys or biometric second factors for sensitive roles like payroll or finance.

How long is the audit trail retained?

Retention follows your data policy. The default is seven years, aligned to common statutory and audit requirements, but it can be extended. The trail is tamper-evident, no record can be silently altered or deleted.

Where is our data stored?

Data is hosted on encrypted, geographically replicated infrastructure. Data residency options are available for organisations with specific jurisdictional requirements, contact us during your compliance check and we will confirm the arrangement.

Do you support single sign-on (SSO)?

Yes. SAML 2.0 and OIDC are supported on Enterprise plans, so your team can sign in through your existing identity provider with the same role-based permissions applied inside CromaHR.

Where is our data physically stored?

Data is stored on encrypted databases hosted in the United States and backed up to a secondary region. For Kenyan clients subject to the Data Protection Act 2019, data residency options are available. Contact us to discuss your specific residency requirements.

What happens if an employee leaves the company?

Access is revoked immediately on their last working day. Their record is retained per your data retention policy, but they cannot log in, view records or export data. The audit trail of everything they did while employed is preserved permanently.

Can we restrict what specific employees can see?

Yes. The five-level role hierarchy controls what each user can view, edit and approve. A line manager sees only their team; an HR officer sees their department; a payroll clerk sees payslips but not performance reviews. Every access level is configurable.

See it on your own numbers

Fifteen minutes. One page of findings. No pitch.

We review how you run this today and send you a written note. You keep it whether or not you become a customer.

Get your team working with CromaHR.

Start free trial
Chat with us