Security
Last updated: May 28, 2026
An overview of the security controls built into NityaHR.
Network & transport
- HTTPS-only with HSTS.
- TLS 1.2+, modern ciphers, HTTP/2.
Authentication
- Argon2id / bcrypt passwords.
- 2FA (TOTP) opt-in.
- Account lockout after repeated failures.
- Concurrent-session cap; forced sign-out on password change / deactivation / exit.
Encryption
- Sensitive columns (PAN, Aadhaar, UAN, bank, face embeddings, 2FA secrets, SMTP passwords) encrypted at rest.
- TLS 1.2+ for every external connection.
- Backups password-encrypted.
Responsible disclosure
Vulnerability reports: hello@nityahr.com
This is the bundled default content. A super-admin can customise and publish a tenant-specific version from the portal (Settings → Legal Pages).
Questions about this page? Email hello@nityahr.com