Security Overview

Last updated: July 1, 2026

Security is fundamental to how Hafinen builds, operates, and delivers its platform.

Hafinen is designed to help organizations manage sensitive workforce, payroll, recruitment, attendance, compliance, and operational data. We understand the importance of protecting this information and apply security practices intended to safeguard confidentiality, integrity, and availability.

This Security Overview provides transparency into Hafinen’s security practices, infrastructure protections, and operational controls.

Security Principles

Hafinen’s security model is built around five core principles:

  • Confidentiality of customer data
  • Integrity of workforce and payroll records
  • Availability and resilience of services
  • Accountability through auditability
  • Privacy by design

Security controls are integrated into both product design and infrastructure operations.

Infrastructure Security

Hafinen’s infrastructure is hosted using trusted cloud providers and network security vendors.

Core infrastructure providers include Amazon Web Services (AWS), Contabo, and Cloudflare.

Infrastructure protections include network segmentation, firewall controls, distributed denial-of-service (DDoS) protection, traffic filtering, TLS encryption, secure API gateways, secure backups, and environment isolation.

Hafinen maintains production and development environment separation where operationally required.

Encryption

Hafinen protects data using encryption.

Data in Transit

All data transmitted between users, APIs, integrations, and Hafinen systems is protected using TLS encryption.

This includes web traffic, API traffic, webhook communication, and authentication requests.

Data at Rest

Sensitive data stored within Hafinen systems is protected using encryption where appropriate, including credential data, access tokens, system secrets, and backups.

Authentication and Access Controls

Hafinen applies layered access controls.

These include role-based access controls (RBAC), permission-based system access, session validation, password hashing, account recovery protections, access logging, and administrative access restrictions.

Customers are responsible for managing internal user permissions.

Biometric Security

Hafinen supports biometric attendance integrations including fingerprint systems and facial recognition systems.

Hafinen does not store raw biometric images.

Integrated biometric systems store encrypted biometric templates or tokens.

Hafinen processes only attendance events, timestamps, and authentication outcomes required for attendance workflows.

Customers remain responsible for lawful employee notices, consent requirements, and local biometric compliance.

API Security

Hafinen offers APIs and webhook support.

Security controls include token-based authentication, webhook validation, request signing where applicable, rate limiting, abuse monitoring, and access revocation.

API credentials should be stored securely by customers.

Monitoring and Logging

Hafinen continuously monitors for service reliability, suspicious activity, unauthorized access attempts, API abuse, infrastructure anomalies, and failed authentication events.

Security-relevant actions are logged to support investigations and accountability.

Vulnerability Management

Hafinen maintains an ongoing vulnerability management process.

This includes dependency updates, patch management, infrastructure hardening, access reviews, and configuration audits.

Critical vulnerabilities are prioritized based on severity and exposure.

Incident Response

Hafinen maintains an internal incident response process for handling, unauthorized access, service outages, data exposure, security events, and infrastructure failures.

Incident priorities are assessed based on Impact, scope, data sensitivity, and operational risk.

Where legally required or contractually obligated, affected customers will be notified without undue delay.

Business Continuity and Backups

Hafinen maintains backup processes designed to support operational recovery.

These include infrastructure redundancy where applicable, backup retention policies, disaster recovery planning, and restoration testing where operationally required.

While Hafinen maintains continuity procedures, customers are encouraged to maintain independent exports of critical business records.

Data Retention and Deletion

Customer data remains available during active subscription periods.

After termination:

  • customer data may remain available for up to 90 days
  • export requests may be made during this period
  • data may be deleted after the retention period

Retention may extend where legally required.

Employee and Internal Security Practices

Hafinen applies internal operational controls including least-privilege access, credential management, internal access reviews, confidential handling of customer information, and controlled production access.

Access to customer data is restricted to authorized personnel only where necessary.

Subprocessors

Hafinen uses carefully selected subprocessors to support infrastructure, communications, and payments.

A current list of subprocessors is available at:

https://www.hafinen.com/subprocessors

Customer Security Responsibilities

Security is a shared responsibility.

Customers are responsible for user permission management, lawful data collection, secure endpoint devices, credential security, internal HR access governance, lawful biometric collection, lawful payroll handling, and secure integration configurations.

Responsible Disclosure

If you discover a security issue affecting Hafinen, please report it responsibly.

Security reports can be submitted to:

[email protected]

Please include issue description, reproduction steps, affected areas, and supporting evidence where available.

We review all legitimate reports.

Security Updates

Hafinen may update this Security Overview to reflect evolving practices, infrastructure changes, and legal requirements.

আপনি বেছে নিতে পারেন কোন ঐচ্ছিক কুকিজ Hafinen আপনার অভিজ্ঞতা বাড়াতে ব্যবহার করতে পারে। কঠোরভাবে প্রয়োজনীয় এবং নিরাপত্তা কুকিগুলি সর্বদা সক্রিয় থাকে কারণ সেগুলি প্রমাণীকরণ, প্ল্যাটফর্মের নিরাপত্তা, জালিয়াতি প্রতিরোধ এবং পরিষেবাগুলির নির্ভরযোগ্য অপারেশনের জন্য অপরিহার্য৷ আপনি যেকোনো সময় আপনার পছন্দ আপডেট করতে পারেন।

কঠোরভাবে প্রয়োজনীয় কুকিজ

হ্যাফিনেনের নিরাপদে এবং নির্ভরযোগ্যভাবে কাজ করার জন্য এই কুকিগুলি অপরিহার্য। তারা অ্যাকাউন্ট প্রমাণীকরণ, লগইন সেশন, CSRF সুরক্ষা, নিরাপদ সেশন ধারাবাহিকতা, লোড ব্যালেন্সিং এবং অন্যান্য মূল প্ল্যাটফর্ম কার্যকারিতা সমর্থন করে। যেহেতু এই কুকিগুলি পরিষেবাগুলির কাজ করার জন্য প্রয়োজন, সেগুলি অক্ষম করা যাবে না৷

নিরাপত্তা কুকিজ

এই কুকিগুলি সন্দেহজনক কার্যকলাপ শনাক্ত করে, অননুমোদিত অ্যাক্সেস রোধ করে, অপব্যবহার হ্রাস করে, API অনুরোধগুলিকে যাচাই করে, হার সীমিত করার সমর্থন করে এবং প্ল্যাটফর্মের অখণ্ডতা বজায় রাখার মাধ্যমে আপনার অ্যাকাউন্ট এবং পরিষেবাগুলিকে সুরক্ষিত করতে সাহায্য করে৷ এই কুকিজ নিরাপত্তার জন্য প্রয়োজন এবং নিষ্ক্রিয় করা যাবে না.

কার্যকরী কুকিজ

কার্যকরী কুকিজ আপনার পছন্দ মনে রাখে এবং আপনার অভিজ্ঞতা ব্যক্তিগতকৃত করে। তারা ভাষা, টাইমজোন, থিম, অ্যাক্সেসিবিলিটি সেটিংস, ইন্টারফেস কাস্টমাইজেশন এবং ড্যাশবোর্ড পছন্দগুলি সঞ্চয় করতে পারে যাতে আপনি প্রতিবার পরিষেবাগুলি ব্যবহার করার সময় আপনাকে সেগুলি কনফিগার করতে হবে না৷

বিশ্লেষণ কুকিজ

অ্যানালিটিক্স কুকিজ আমাদের বুঝতে সাহায্য করে কিভাবে পরিষেবাগুলি ব্যবহার করা হয় যাতে আমরা ব্যবহারযোগ্যতা, কর্মক্ষমতা এবং নির্ভরযোগ্যতা উন্নত করতে পারি। তারা বৈশিষ্ট্য গ্রহণ, পৃষ্ঠার ইন্টারঅ্যাকশন, নেভিগেশন প্যাটার্ন, ব্রাউজার সামঞ্জস্য, ক্র্যাশ রিপোর্ট এবং কর্মক্ষমতা মেট্রিক্সের মতো তথ্য সংগ্রহ করে। যেখানে সম্ভব, এই তথ্য একত্রিত বা বেনামী করা হয়.

কর্মক্ষমতা কুকিজ

কর্মক্ষমতা কুকিজ পরিষেবাগুলির গতি, স্থিতিশীলতা এবং প্রতিক্রিয়াশীলতা উন্নত করে৷ তারা ক্যাশিং, কন্টেন্ট ডেলিভারি অপ্টিমাইজেশন, ট্র্যাফিক ব্যালেন্সিং, অ্যাসেট লোডিং এবং অন্যান্য প্রযুক্তি সমর্থন করে যা একটি সামঞ্জস্যপূর্ণ এবং নির্ভরযোগ্য ব্যবহারকারীর অভিজ্ঞতা প্রদান করতে সহায়তা করে।

যোগাযোগ কুকিজ

যোগাযোগ কুকিজ পরিষেবা-সম্পর্কিত মিথস্ক্রিয়াকে সমর্থন করে যেমন বিজ্ঞপ্তি ডেলিভারি, ইমেল ইভেন্ট ট্র্যাকিং, এসএমএস নিশ্চিতকরণ, এবং অন্যান্য অপারেশনাল যোগাযোগ কর্মপ্রবাহ যা পরিষেবাগুলি ব্যবহার করার সময় আমরা আপনাকে কীভাবে অবগত রাখি তা উন্নত করে।