Security controls for sensitive workforce data
Workforce data deserves careful control. ProTrack uses Firebase and Google Cloud services, role-based application access and secure transport while we continue to strengthen our documented security programme.
Make the process easier to understand and question.
Identity and access
Firebase Authentication protects user sign-in. Application roles limit access to organisation data and sensitive views. Customers should enforce strong account practices, remove departed users promptly and review access regularly.
- Organisation-scoped access controls
- Server-verified session cookies
- Role-based dashboard permissions
Application and infrastructure
The web application is delivered over HTTPS with security response headers. Production secrets are referenced through managed configuration rather than published in browser code. Data services are hosted on Google Cloud and Firebase.
Operational safeguards
We maintain security remediation records, dependency checks and deployment controls. Incident response, access review, backup testing and supplier review are ongoing programme activities rather than one-time claims.
Shared responsibility
Customers decide what to monitor, who may access it and how long it is needed. A secure product cannot make an excessive or undisclosed monitoring deployment lawful or fair.