We protect your data, infrastructure, and operations using industry-standard controls, modern encryption, and continuous monitoring so you can focus on growth with confidence.
Well-planned compensation isn’t just about pay, it’s about trust, motivation, and long-term retention.
Real-time monitoring and automated alerts help us identify unusual activity and potential threats as they occur.
Documented response procedures enable fast investigation, mitigation, and communication in the event of a security incident.
Multi-zone deployment ensures resilience and continuous service availability, even during infrastructure disruptions.
AWS-managed databases with automated backups and multi-zone deployment.
Multiple retention points ensure data is never lost.
TraineryHCM maintains SOC 2 Type II certification, which requires annual third-party audits of security, availability, processing integrity, confidentiality, and privacy controls. SOC 2 Type II is the benchmark security standard for enterprise SaaS platforms storing sensitive HR and compensation data. Customers can request TraineryHCM's SOC 2 report under NDA as part of their vendor security due diligence process.
Employee data in TraineryHCM is encrypted in transit using TLS 1.2 and above, and encrypted at rest using AES-256 encryption. All data is stored in SOC 2-certified cloud infrastructure with redundant backups and geographic failover. Access to production data is restricted to authorized personnel through multi-factor authentication and role-based access controls. All data access events are logged in a tamper-evident audit trail available to security administrators.
Role-based access control (RBAC) is a security model that restricts system access based on each user's defined role. In TraineryHCM, access permissions are assigned by role (employee, manager, HR administrator, executive) with fine-grained controls over which data each role can view, edit, or export. A manager sees only their direct reports' performance and development data. Compensation data is restricted to HR administrators and approved leaders based on configurable permission levels.
Yes. TraineryHCM maintains a comprehensive audit log that records every data access, modification, and export event across the platform, including who performed the action, when it occurred, what data was affected, and from which IP address. Audit logs are available to HR security administrators and can be exported for internal audits, regulatory reviews, or security incident investigations. Log retention periods are configurable based on organizational data governance requirements.
TraineryHCM hosts customer data in enterprise-grade cloud infrastructure with primary and secondary data centers in the United States. Data residency requirements for specific geographies (such as GDPR requirements for EU employee data) can be accommodated through regional hosting configurations. Customers requiring specific data residency terms can review TraineryHCM's data processing agreement and request regional hosting options during the contract and implementation process.
TraineryHCM supports GDPR compliance through data subject access request (DSAR) workflows, configurable data retention periods, employee consent management, right-to-erasure functionality, and a data processing agreement (DPA) that meets EU and UK GDPR requirements. HR administrators can generate DSAR reports, initiate data deletion workflows, and review consent logs from within the platform's compliance administration panel without requiring IT intervention.
TraineryHCM provides a structured data export process that allows customers to export all their employee, performance, learning, and compensation data in standard formats (CSV, JSON) at any time, including at the end of a contract. Data export requests are fulfilled within a defined SLA. After the contract termination period, all customer data is securely deleted from TraineryHCM's systems in accordance with the data retention terms of the customer's service agreement.
Compensation data in TraineryHCM (salary records, merit decisions, pay equity analysis, equity grant details) is subject to elevated access controls beyond standard employee data. Only HR administrators and explicitly authorized leaders with compensation roles can access CompBldr's salary and planning data. All compensation data exports are logged with user identification and timestamp. TrAI's pay equity analysis outputs are visible only to designated compensation administrators, not to managers or employees.
Move beyond manual spreadsheets and inconsistent decisions. Design structured, performance-aligned compensation plans that employees trust and leaders can confidently approve.