Trust Centre

Everything your security team needs, in one place.

EMPLOI employs people on your behalf, which means we hold payroll, identity, and employment data. This page sets out our current certification status, security controls, sub-processors, insurance, and legal entity structure so your vendor review can move quickly.

This page is maintained by EMPLOI to answer common security and privacy questions about our service. It describes our own practices and is not an independent audit, certification, or attestation. Where a certification is still in progress, we say so plainly.

Certification and compliance status

SOC 2 Type II

In progress

We are working towards a SOC 2 Type II report covering security and availability. Observation window and auditor details can be shared under NDA. No report has been issued yet, and we do not describe ourselves as SOC 2 certified.

ISO 27001

Aligned, not certified

Our information security programme is structured against the ISO/IEC 27001 control families: access control, asset management, supplier security, incident response, and business continuity. We are not ISO 27001 certified and do not hold a certificate.

POPIA

Operating practice

As a South African employer we process employee personal information under POPIA, South Africa's GDPR-grade privacy law, with a registered Information Officer and published notice.

GDPR / UK GDPR

Contractual commitments

Where clients are subject to GDPR, we sign a data processing agreement with standard contractual clauses for transfers to South Africa.

Controls summary

Security controls we operate today.

Access control

  • Single sign-on with enforced multi-factor authentication for internal systems.
  • Role-based access, granted on least privilege and reviewed when roles change.
  • Access revoked as part of the documented offboarding checklist.

Data protection

  • Data encrypted in transit with TLS and at rest by our infrastructure providers.
  • Payroll and identity data restricted to the payroll and HR teams that need it.
  • No production personal data used in test or demo environments.

People

  • Background and reference checks on EMPLOI staff and placed employees.
  • Confidentiality and IP assignment terms in every employment contract.
  • Security and privacy awareness training at onboarding and annually.

Operations

  • Documented incident response process with a named owner and client notification steps.
  • Change management and code review for anything touching client data.
  • Vendor review before any new sub-processor handles client or employee data.

Endpoints and workspace

  • Company-managed devices with disk encryption, screen lock, and endpoint protection.
  • Secured office and remote-work standards, including network and workspace requirements.
  • Password manager required for all shared credentials.

Continuity

  • Payroll run redundancy so pay dates are met if a key person is unavailable.
  • Backups of core HR and payroll records held by our systems providers.
  • Documented runbooks for payroll, onboarding, and offboarding.

Documentation

Data Processing Agreement

Our standard DPA covers roles and responsibilities, categories of data, security measures, sub-processing, international transfers with standard contractual clauses, breach notification, and deletion on termination.

Tell us where to send it and we will email the current version, along with our security questionnaire responses if you need them.

Emailed within one business day

Sub-processors

These are the categories of third parties that may process client or employee personal data on our behalf. Named entities, locations, and contract terms are provided in the sub-processor schedule attached to the DPA. We notify clients before adding a sub-processor that handles their data.

CategoryPurposeProcessing location
South African payroll bureauPayroll calculation, payslips, and statutory filings (PAYE, UIF, SDL)South Africa
HR information systemEmployee records, contracts, leave, and onboarding workflowsSouth Africa / EU
Cloud infrastructure and hostingHosting of EMPLOI web properties and internal toolingUnited States / EU
Business productivity suiteEmail, documents, and internal collaborationUnited States / EU
CRM and marketing platformClient contact records, scheduling, and communicationsUnited States
Banking and payment partnersUSD invoicing and ZAR salary disbursementUnited States / South Africa

Insurance

Employers' liability and COIDA

All employees are covered under South Africa's Compensation for Occupational Injuries and Diseases Act fund, contributed to monthly as the legal employer.

Professional indemnity

Cover held for professional services rendered to clients. Certificates and limits shared on request during procurement.

Cyber liability

Cover in place for data incidents affecting client and employee information. Limits confirmed in writing under NDA.

Entity structure

EMPLOI operates as two sister companies. Your commercial contract sits with the US entity; the employment contract sits with the South African entity that is the legal employer of record.

United States

EMPLOI Inc.

  • Contracting party for US clients, invoiced in USD.
  • Owns the client relationship, service levels, and commercial terms.
  • Signs the master services agreement and the DPA with you.

South Africa

Veridian Global (Pty) Ltd

  • The in-country legal employer of your South African team.
  • Registered with the South African revenue service (SARS) for payroll withholding, unemployment insurance (UIF), and the skills development levy (SDL).
  • Holds employment contracts under South Africa's core employment statute (the BCEA) and the Labour Relations Act.

Sister companies under common ownership. Registration numbers, directors, and proof of good standing are provided during vendor onboarding.

Report a security issue

Email security@emploieor.com with details and steps to reproduce. We acknowledge reports within one business day and will keep you updated until the issue is closed. Please do not access or modify data that is not yours while testing.

Privacy requests

Employees, candidates, and clients can request access, correction, or deletion of their personal information at popia@emploieor.com. See our POPIA notice and privacy policy.

Still have questions from your security review?

Bring your questionnaire. We will walk through it line by line.

Book a Call

Already paying South African contractors? Long-term contractors who work like employees are a misclassification claim waiting to happen: back pay, penalties, and an ugly CCMA (Commission for Conciliation, Mediation and Arbitration) case. Converting them to compliant EOR employment takes about two weeks.

See how conversion works