Your HR, payroll, contracts and business secrets are protected by the strictest industry standards. You can verify it yourself.
Multiple layers lock down access to your workspace. No login goes unnoticed.
Every login is logged with timestamp, browser, device and IP. Browse the last 90 days from your profile.
Your team authenticates with phone + a unique PIN sent via activation email. No password to remember.
5 failed attempts = automatic 15-minute lockout. You're alerted of any suspicious activity on your account.
See in real time every device connected to your account. Revoke remotely in one click anything that shouldn't be there.
Admin, HR, Manager, Employee, CFO, Accountant... each role only sees and edits what they should. Strict least-privilege principle.
Strict policy: minimum 8 characters, mix of uppercase/digits/symbols. Hashed with bcrypt — never stored in plaintext, even on our side.
Your data is encrypted end-to-end, isolated per company, and continuously backed up.
All browser ↔ server communications are encrypted with TLS 1.3, the latest banking-grade standard.
Every company lives in its own logical compartment. A request from company A technically cannot reach company B's data.
Encrypted snapshots of the database every 24h, retained for 30 days, restorable in under 4 hours when needed.
Kubernetes-containerized infrastructure, data hosted in ISO 27001-certified datacenters with multi-zone redundancy.
Right to export, rectify, and be forgotten. Named audit logs retained 7 years to meet legal and contractual requirements.
Upstream WAF blocks known attacks (SQL injection, XSS, CSRF, DDoS) before they even reach the application.
We're never satisfied. Every deployment goes through a battery of automated and manual checks.
Full security test suite (RBAC, injections, brute-force, webhook signatures...) run before every production release. 100% coverage.
GitHub Actions pipeline with npm/pip audit on every commit, secret scanning, static lint, mandatory review before merge.
Pentest performed yearly by an independent third-party firm (report available on request under NDA).
Found a vulnerability? Email security@gespo.digital — we guarantee acknowledgment within 24h and a documented fix.
Our security team responds personally within 24 hours, 7 days a week.
security@gespo.digital