Skip to main content

Security & trust

Your data is in safe hands

Security isn't a feature we added later - it's built into every layer of PurpletGo. Your employee records, compliance documents, and team credentials are protected the way your compliance team expects. Share this page with your infosec team.

SOC 2GDPRISO 27001HIPAACCPAPCI DSS

Your credentials are never at risk

Even if our database were ever breached, your passwords cannot be recovered or reused. Every credential is protected with industry-standard one-way encryption before it ever touches storage.

Your data is completely isolated

Every organisation's data is isolated at the database row level using strict org_id partitioning - enforced in every query, not just application code. One tenant's records are never accessible to another.

Remove access instantly

When an admin or team member leaves, changing their password immediately cuts off every active session and device - nothing to revoke by hand, nothing left running in the background.

Compliance documents stay private

NDAs, exit interviews, and sensitive files are stored in a private vault with no direct public links. Only authorised users can view them, and every access automatically expires - no accidental exposure.

We never see your GitHub credentials

Your GitHub connection is authorised directly through GitHub - we never store tokens you would need to rotate if you left. Revoke access from GitHub at any time with a single click.

Every integration credential is encrypted at rest

API tokens, keys, and secrets for every connected app - Jira, Slack, AWS, and more - are encrypted with AES-256-GCM before they ever touch the database. A database breach alone can never expose a working credential.

Protected from automated attacks

Repeated login attempts are automatically detected and blocked before they can cause harm. Your team accounts are shielded from brute force and credential-stuffing attacks around the clock.

Complete paper trail for every action

Know exactly who did what and when - every access revocation, document upload, and team change is logged with full context. Invaluable for HR disputes, compliance reviews, and security investigations.

Protected against common web attacks

Industry-standard browser protections are enabled on every page to prevent hijacking, phishing overlays, and malicious script injection - keeping your team safe from threats they would never see coming.

Two-factor authentication for every account

Every team member can enable TOTP-based two-factor authentication directly from their profile. A time-based one-time code is required at login - so a stolen password alone is never enough to get in.

All traffic encrypted with TLSNo cross-tenant data access - everFile uploads validated for type and sizeRole-based permissions on every actionNo third-party tracking in the product

Have a security question?

Reach out to our team directly, or start a free trial to see the platform yourself.