Security built around your own data
Employee records are the most sensitive data a company holds. PeopleMuster keeps each company's data in its own database and controls who sees what, down to the field.
Each company runs on its own database, in its own account, in the region it picks when we set it up. There are no shared tables with other companies, so one customer's records are never a query away from another's.
Access rules are enforced in the database itself through row-level security, as well as on screen. On top of that sit five built-in roles and sixty-four discrete permissions across attendance, leave, projects, benefits, devices and the rest. Create your own roles, and changes take effect at the person's next sign-in.
Every change is recorded. The activity log keeps field-level before-and-after values, so a disputed leave balance or a changed timesheet status has a trail rather than an argument.
At a glance
How PeopleMuster protects the people data you put into it.
| Area | How it works |
|---|---|
| Where data lives | Your own database, in your own account, in the region you choose |
| Sign-in | Passwordless: a one-time code sent to the person's work email, behind bot protection |
| Access control | Row-level security in the database, 5 built-in roles, 64 permissions, custom roles |
| Audit trail | Field-level before-and-after values on every change, filterable by person and date |
| Biometric data | Fingerprints stay on the terminal. PeopleMuster receives only who punched and when |
| Integration keys | Stored per company and masked in the interface once saved |
| In the browser | HTTPS only, with security headers that block framing and limit where scripts load from |
| Sensitive feedback | Identities masked by default, with every reveal recorded in the activity log |
The checklist buyers use
Seven questions come up in almost every HR software security review. Here is what the market publishes against each one, read on 12 vendors' own security pages in September 2026.
You'll find the same seven items on a procurement form or a vendor questionnaire. Bring them to any vendor, including us. Every figure below describes the market as a whole and is claimed for nobody: they tell you what a typical answer looks like, so you can judge each vendor's answer on its own.
| What buyers ask | What the market publishes (September 2026) |
|---|---|
| Single sign-on | 10 of 12 vendors publish it, and at 5 of them it sits behind a higher plan |
| Two-factor sign-in | 9 of 12 publish it, usually optional by default and enforceable by an admin |
| Backups | Where a schedule is published, the usual word is daily |
| Uptime | A 99.9% figure where one is published; 4 of 12 publish one |
| Certifications | SOC 2 Type II and GDPR are the pair most vendors name |
| Hosting region | A named region, or a choice between a US and an EU location |
| Status page | A public status page on the vendor's own subdomain |
Read on each vendor's own security or trust page in September 2026. Figures describe the market, not any one product.
Two of the seven are worth pressing on. Ask where the region is chosen and by whom, because a fixed region is a decision the vendor made for you. And ask whether the answer to "who can see this field" is enforced in the database or only in the screens, because a screen can be bypassed and a database rule can't.
How PeopleMuster answers
Every line here is read from the product's source code, not from a policy document. Bring the checklist above and hold it against this.
| The question | PeopleMuster's answer |
|---|---|
| Where is our data hosted? | In your own database, in your own account, in the region you choose when we set it up. Nothing is pooled with another customer. |
| How do people sign in? | With a one-time code sent to their work email, behind bot protection. There is no password to reuse, phish or leak. |
| Who can see what? | Five built-in roles, 64 permissions and your own custom roles, enforced by row-level security in the database itself. |
| What gets recorded? | Every change, with field-level before-and-after values, filterable by person and by date. |
| What happens to fingerprints? | They stay on the terminal. PeopleMuster receives only who punched and when. |
| What protects the browser session? | HTTPS only, with strict browser security headers, including a content security policy and a block on framing by other sites. |
| Who sets it up? | We do, with you: your modules, your roles and your people, on your own account. |
Your own account is the part that changes the conversation. The market's usual answer is a named region or a US-or-EU choice; with PeopleMuster you pick the region, and the database sits in an account you hold. That also settles the exit question: the database is in your account from day one. It's included in the $3 per person, per month price, with every module.
Fingerprint attendance, handled carefully
If you use a fingerprint terminal, the terminal does the matching. PeopleMuster never receives or stores a fingerprint. What it syncs is the terminal's user number and the time of each punch, which is all attendance needs. PeopleMuster's ZKTeco sync pulls those punches from the terminal over your local network, with nothing installed on the device.
A terminal is optional. An admin can turn on browser check-in instead, so people check in from the web inside their shift window.
Questions people ask
Where is our data stored?
In your company's own database, in your own account, in the region you choose when we set it up. It is not shared with any other customer.
How do people sign in?
With a one-time code sent to their work email. There is no password to reuse, phish or leak, and the sign-in form sits behind bot protection.
Can an administrator see everything?
Administrator is one of five roles and carries the widest permission set. Feedback is identity-masked by default, with an explicit reveal action that is itself recorded in the activity log.
Where are integration keys kept?
Per company, in that company's own database, and masked in the interface after they are saved. They are never shown again in full.
Who chooses the hosting region?
You do. Each company's database is created in its own account, in the region chosen at setup, and it stays there. The market's usual answer is a region the vendor named, or a choice between a US and an EU location.