Your people's data, treated like it matters
Payroll and HR hold the most sensitive data a company keeps. Comsky HRMS is built DPDP-aware from the data model up — encryption, role-scoped access, verified tenant isolation and an immutable audit trail. Here is how it works, described plainly and without over-claiming.
Encryption at rest & in transit
Sensitive identifiers — PAN, bank details and similar fields — are encrypted at rest with field-level encryption. Traffic to the application is served over TLS, and secrets are never shipped to the browser.
Role-based access control
A base RBAC model with granular custom roles layered on top means people see only what their role allows. Approval workflows and delegation are configurable per company.
Verified tenant isolation
Every query is scoped to your company, backed by Postgres row-level security. Cross-tenant access is designed out at the data layer, not policed after the fact.
Append-only audit trail
Who changed what, when, and from which IP — recorded to an immutable, append-only log across every module, so activity can be reconstructed for accountability.
Authentication by Comsky Identity
Sign-in is delegated to central Comsky Identity (account.comsky.in) — MFA-ready and session-managed. Comsky HRMS stores no password of its own.
Backups & recovery
Your data is backed up regularly so it can be restored in the event of an incident, and recovery procedures are part of how the service is operated.
Aligned with India's data-protection law
The Digital Personal Data Protection framework expects organisations to handle personal data with clear purpose, controlled access and demonstrable accountability. Comsky HRMS is designed to help you meet those expectations — for your own team and as a processor of your employees' data.
- ✓DPDP-aware data handling built into the product, not added as an afterthought
- ✓Support for data-principal rights — access, correction and erasure workflows
- ✓Purpose-scoped access to personal data, with an audit trail for accountability
- ✓Clear separation between your company’s data and every other tenant’s
Residency, access and integrity
India data residency
Your company and employee data is hosted in India.
Least-privilege access
Administrative access to systems is limited and controlled on a need-to-know basis.
Scoped API access
The public REST API uses scoped keys, and outbound webhooks are signed, so integrations get only what they need.
Reproducible runs
Payroll runs are immutable and idempotent, so a historical result can always be reproduced for verification.
Who else touches the data
Comsky HRMS connects to a small set of external services to do its job. Many of these are things you initiate — a filing you submit or a payment file you process — rather than continuous data sharing.
Shared responsibility
We secure the platform — encryption, isolation, audit and the infrastructure it runs on. You control who in your organisation has which role, keep the right people as administrators, and manage sign-in through your Comsky account. Good security is a partnership, and the RBAC and audit tools are there to help you hold up your side.
Responsible disclosure
If you believe you have found a security issue, we want to hear about it. Please email support@comsky.in with the details and steps to reproduce, and give us a reasonable window to investigate and respond before any public disclosure.
We describe the controls that are in place today and avoid claiming certifications we do not hold. If you have specific security or compliance requirements for a procurement review, get in touch and we will walk through them with you.
Security questions before you start?
Read how we handle personal data, or reach out and we will answer whatever your review needs.