Security & data protection

Your people's data, treated like it matters

Payroll and HR hold the most sensitive data a company keeps. Comsky HRMS is built DPDP-aware from the data model up — encryption, role-scoped access, verified tenant isolation and an immutable audit trail. Here is how it works, described plainly and without over-claiming.

🔏

Encryption at rest & in transit

Sensitive identifiers — PAN, bank details and similar fields — are encrypted at rest with field-level encryption. Traffic to the application is served over TLS, and secrets are never shipped to the browser.

🧑‍⚖️

Role-based access control

A base RBAC model with granular custom roles layered on top means people see only what their role allows. Approval workflows and delegation are configurable per company.

🧱

Verified tenant isolation

Every query is scoped to your company, backed by Postgres row-level security. Cross-tenant access is designed out at the data layer, not policed after the fact.

📜

Append-only audit trail

Who changed what, when, and from which IP — recorded to an immutable, append-only log across every module, so activity can be reconstructed for accountability.

🪪

Authentication by Comsky Identity

Sign-in is delegated to central Comsky Identity (account.comsky.in) — MFA-ready and session-managed. Comsky HRMS stores no password of its own.

💾

Backups & recovery

Your data is backed up regularly so it can be restored in the event of an incident, and recovery procedures are part of how the service is operated.

DPDP & compliance

Aligned with India's data-protection law

The Digital Personal Data Protection framework expects organisations to handle personal data with clear purpose, controlled access and demonstrable accountability. Comsky HRMS is designed to help you meet those expectations — for your own team and as a processor of your employees' data.

  • DPDP-aware data handling built into the product, not added as an afterthought
  • Support for data-principal rights — access, correction and erasure workflows
  • Purpose-scoped access to personal data, with an audit trail for accountability
  • Clear separation between your company’s data and every other tenant’s
How the service is run

Residency, access and integrity

🇮🇳

India data residency

Your company and employee data is hosted in India.

🔐

Least-privilege access

Administrative access to systems is limited and controlled on a need-to-know basis.

🧩

Scoped API access

The public REST API uses scoped keys, and outbound webhooks are signed, so integrations get only what they need.

♻️

Reproducible runs

Payroll runs are immutable and idempotent, so a historical result can always be reproduced for verification.

Third parties

Who else touches the data

Comsky HRMS connects to a small set of external services to do its job. Many of these are things you initiate — a filing you submit or a payment file you process — rather than continuous data sharing.

C
Comsky Identity
Authentication, single sign-on and session management (account.comsky.in).
S
Statutory portals
EPFO, ESIC and TRACES — for the filing artifacts you generate and submit.
B
Banking channels
NEFT / host-to-host files for salary and vendor payouts that you process.
N
Notification channels
Email and, where enabled, Slack or Microsoft Teams for approvals and alerts.

Shared responsibility

We secure the platform — encryption, isolation, audit and the infrastructure it runs on. You control who in your organisation has which role, keep the right people as administrators, and manage sign-in through your Comsky account. Good security is a partnership, and the RBAC and audit tools are there to help you hold up your side.

Responsible disclosure

If you believe you have found a security issue, we want to hear about it. Please email support@comsky.in with the details and steps to reproduce, and give us a reasonable window to investigate and respond before any public disclosure.

We describe the controls that are in place today and avoid claiming certifications we do not hold. If you have specific security or compliance requirements for a procurement review, get in touch and we will walk through them with you.

Security questions before you start?

Read how we handle personal data, or reach out and we will answer whatever your review needs.