What will a security review of PeopleMuster find?

A security review of PeopleMuster finds a separate database for each customer, held in the customer's own account and region. Sign-in uses a one-time email code behind bot protection. Access rules are enforced in the database, the app is served over HTTPS only with strict headers, and fingerprints never leave the terminal.

Vendor questionnaires ask the same handful of things. Here are the answers, in the order reviewers usually ask them.

Hosting and tenancy. Each customer gets its own database, set up in the customer's own account, in a region the customer picks. There are no shared tables with another company.

Identity. People sign in with a six-digit code sent to their work email, so there are no passwords to store. Turnstile guards the form, and each person can see and end their own sessions.

Authorisation. Five roles and sixty-four permissions, with custom roles on top. Access rules are also enforced in the database, not only on the screen.

Transport. HTTPS only, with strict transport security, a content security policy, and framing blocked so the app cannot be loaded inside another site.

Secrets. Integration keys are stored in your own database and masked once saved.

Logging. Every create, update and delete is recorded with before and after values, the person and the time.

Biometrics. Fingerprints stay on the terminal. The sync stores only the device user, the terminal serial and the punch time.

Related questions

Where is our data hosted?

In your own database, in your own account, in the region you choose at setup.

Does PeopleMuster store fingerprints?

No. Fingerprints stay on the terminal. PeopleMuster receives only who punched and when.

Who sets the instance up?

We do, with you. We deploy into your project and set up your modules, your roles and your integrations.