Security
At PeopleWeek, security and data protection are embedded in everything we do.
At PeopleWeek, security and data protection are embedded in everything we do.
Security is embedded in PeopleWeek’s culture. We have established organisational practices and controls designed to protect customer data and uphold the highest standards of privacy and security.
PeopleWeek’s IT Security Committee meets monthly to monitor the evolving security landscape, review emerging risks, and ensure our Information Security Management System (ISMS) continues to meet the highest standards. With our Managing Directors actively involved, security remains a priority with clear ownership and accountability at the highest levels of the organisation.
PeopleWeek conducts regular cyber security audits and penetration testing of our platform. We comply with data protection legislation, including GDPR and the Swiss Federal Act on Data Protection (FADP). PeopleWeek’s customers can request a summary of our latest external penetration testing results. PeopleWeek’s customers may also request to conduct their own, independent penetration testing of our platform.
PeopleWeek is ISO 27001 certified, the internationally recognised standard for information security management. This certification confirms that we apply strict processes to protect data confidentiality, integrity, and availability, and continuously assess and improve our security controls. Certification audits are conducted by SGS Switzerland.
PeopleWeek’s application architecture has been developed to OWASP® standards. Open Web Application Security Project® is a nonprofit foundation that works to improve the security of software. OWASP outlines more than 80 critical security risks for web application security. PeopleWeek has incorporated these standards into its software design and we self-audit our robustness.
PeopleWeek uses role-based access control to ensure users only access the information required for their responsibilities. This approach provides a secure and scalable way to manage data access across organisations of all sizes.
With more than 50 predefined roles covering areas such as HR, management, recruitment, training, compensation, talent, expenses, and compliance, PeopleWeek enables organisations to apply precise access controls based on their structure and requirements. Roles can vary depending on the modules implemented by each customer.
These security roles are built into the PeopleWeek platform rather than being individually configured for each customer. This built-in privacy approach reduces the risk of configuration errors and helps ensure that users have the appropriate level of access at all times.
PeopleWeek has encryption on multiple levels: at infrastructure level (i.e. full disk encryption), at database level, and at file level.
PeopleWeek offers a native login that follows recognised secure password protocols. We also offer dual factor authentication, including a proprietary application for generating time-based one-time passwords (TOTP).
Many PeopleWeek customers have chosen to integrate PeopleWeek with Azure Single Sign-On, which offers their employees a convenient method for accessing the system and can be combined with multi-factor authentication (MFA).
All log-in methods work on the Web version and mobile app version of PeopleWeek.
All PeopleWeek servers are hosted in top tier data centres are in Switzerland. Both our primary and fall-back data centres are in Switzerland.
PeopleWeek can recover up to 30 days of customer data and archives. It is also possible for clients to have a longer data recovery period (subject to additional fees).
PeopleWeek’s approach to managing client instances enables us to employ horizontally scalable resources. This means that if a hardware or software problem renders the service unavailable for a specific client, PeopleWeek’s infrastructure uses pooled resources to take over the load, thereby providing uninterrupted service. The pooling of server resources also means that client data is continuously replicated to minimise the potential data-loss window in a disaster recovery scenario.
PeopleWeek can make available to our clients and prospective clients the following documents:
PeopleWeek’s Information Security Manager & Data Protection Officer is also available to address security related questions (chris.parker@peopleweek.com).
PeopleWeek takes data security very seriously. Our aim to not to merely comply with legal and regulatory requirements, but to exceed them to continuously adapt our practices in line with evolving technologies and risks.
PeopleWeek complies with GDPR and Swiss Federal Act on Data Protection (FADP). We ensure that our employees are well trained and have the required tools to be able to respect data privacy and protection requirements. Our IT Security Committee meets monthly to ensure that senior management remains very focused on all aspects of IT security, and that security and data protection are embedded in our working practices and culture.
PeopleWeek’s IT security, data protection and data privacy policies can be shared with clients and prospects on demand.
All client data and files are hosted in top tier data centres in Switzerland.
PeopleWeek has a 30-day data retention practice. Clients can request longer retention periods (subject to additional fees). All client databases and files, as well as back-up servers, are hosted in Switzerland.
PeopleWeek has encryption on multiple levels: at infrastructure level (i.e. full disk encryption), at database level, and at file level.
PeopleWeek uses encryption in transit, encryption at rest. Encryption is at the level of the disk, database, and files.
PeopleWeek stores and monitors various application and system level logs. Furthermore, PeopleWeek stores a detailed audit log of the business transactions taking place in the application that can be made available to clients upon request.
chris.parker@peopleweek.com (Chief Information Security Officer and Data Protection Officer)
PeopleWeek’s BCP can be shared with clients and prospects on demand.
Yes
PeopleWeek follows a strict change management process for all system updates. All changes are captured in change logs.
PeopleWeek is ISO 27001 certified, the internationally recognised standard for information security management. This certification confirms that we apply strict processes to protect data confidentiality, integrity, and availability, and continuously assess and improve our security controls. Certification audits are conducted by SGS Switzerland.
PeopleWeek performs internal vulnerability scans at regular intervals to test our application and infrastructure. In addition, independent penetration testing is performed by a Swiss external cyber security company annually to identify any vulnerabilities.
A summary report can be shared with clients and prospects on demand.
Send an email to admin@PeopleWeek .com
PeopleWeek’s incident management policy can be shared with clients and prospects on demand.
Access to customer data is strictly controlled based on role and business need. Level 1 support teams do not have access to customer data, while Level 2 support is restricted to authorised members of the IT Security & Data Protection Team. Infrastructure engineers can only access production environments through Just-In-Time (JIT) access controls, with all access protected by security measures such as corporate network restrictions and multi-factor authentication.
PeopleWeek regularly trains its employees on information security and data protection topics.
In the unlikely event of a data breach or potential data breach, PeopleWeek follows its incident management policy. Our incident management policy includes protocols on communication with clients and any regulatory authorities.
PeopleWeek offers two different types of user authentication:
1) Login using PeopleWeek native login, which complies with security protocols such as unique user names, complex passwords and support for enabling or mandating built in two-factor authentication using “Time-based One-Time Passwords” (TOTP). PeopleWeek has its own TOTP application
2) Azure Single Sign-On (SSO).
PeopleWeek is built on role-based access control, ensuring that users only have access to the information relevant to their responsibilities. With more than 50 predefined roles, PeopleWeek ensures that each user only accesses the data appropriate to their role.
PeopleWeek’s infrastructure has been designed to optimise performance, reliability, and durability for all clients. We have in-built redundancy and replication capabilities through the design of our database, files, and server architecture. This is underpinned by our application and infrastructure security, as well as mature working practices.
In the unlikely event of a total failure of PeopleWeek, 30 days’ of backed-up data can be restored. As client data is continuously replicated using our pooled resources, the window for possible data-loss is minimised in a disaster recovery scenario.
The customer is the owner and controller of its data stored in PeopleWeek.
Upon termination of the contractual relationship, customers can extract most of their data and documents directly from PeopleWeek. Where additional assistance is required, PeopleWeek can support customers with data extraction, including bulk document exports where appropriate. Following the completion of the agreed data extraction process, customer data is securely deleted in accordance with PeopleWeek’s data retention procedures.