Security & compliance

Enterprise-grade security.

ShiftTracker runs on UK/EU cloud infrastructure with TLS in transit, encryption at rest, hardened authentication, and role-based access controls, backed by documented incident response. Our hosting provider is independently audited to SOC 2 Type II.

01 / DATA PROTECTION

How does ShiftTracker protect customer data?

Security controls include UK/EU cloud infrastructure, encryption at rest, encryption in transit with TLS, hardened authentication (hashed passwords, account lockout, rate limiting), role-based access controls, and documented incident response procedures.

UK/EU Cloud Infrastructure

ShiftTracker runs on UK/EU cloud infrastructure whose provider is independently audited to SOC 2 Type II, supporting data residency requirements.

Encryption at Rest

Data is encrypted at rest by our cloud infrastructure.

TLS in Transit

Data is encrypted in transit using TLS, with HTTPS enforced (HSTS).

Hardened Authentication

Passwords are hashed with bcrypt, repeated failed sign-ins are locked out, and authentication is rate-limited.

Role-Based Access

Role-based access controls restrict data to authorised users within each organisation.

Documented Incident Response

Security incidents follow documented procedures including containment, required notifications, and post-incident review.

02 / GDPR & COMPLIANCE

Is ShiftTracker GDPR compliant?

ShiftTracker is built to align with UK GDPR and is hosted on UK/EU cloud infrastructure to support data residency and compliance requirements.

AreaStatusDetails
UK GDPRAlignedBuilt to align with UK GDPR
Cloud InfrastructureActiveUK/EU cloud infrastructure for data residency
Hosting ProviderActiveIndependently audited to SOC 2 Type II
Encryption in TransitActiveTLS, with HTTPS enforced (HSTS)
Encryption at RestActiveProvider-managed encryption at rest
Access SecurityActiveHashed passwords, account lockout, rate limiting, RBAC
Incident ResponseActiveDocumented procedures with required notification timelines
03 / DATA HOSTING

Where is ShiftTracker data stored?

ShiftTracker runs on UK/EU cloud infrastructure for performance and data residency. Regular automated backups support disaster recovery.

Infrastructure
UK/EU cloud
Data residency
UK/EU
Hosting provider
SOC 2 Type II
Encryption in transit
TLS
Encryption at rest
Enabled
Backups
Automated
Access controls
RBAC
GDPR
UK GDPR-aligned

Need more details?

For security or data protection questions, contact our team and we will share the relevant policy details.