Security & privacy

Built for the most sensitive data you hold.

Paritir processes pay, gender and role data to help you meet the EU Pay Transparency Directive — so privacy and security aren't a feature, they're the foundation. Here's how we protect it: in plain language, and accurate to how the platform actually works.

Privacy by design

Minimise, then protect

We collect only what the obligation needs, pseudonymise personal identifiers before analysis, and never surface an individual. Privacy is engineered into each step, not bolted on.

EU-first

Your data stays in Europe

Compute and storage run in EU regions, and AI processing is moving to EU-region inference. We self-host our fonts, and any analytics are cookieless and aggregate — no advertising or cross-site trackers.

Isolated by tenant

Your data is only yours

Every query is scoped to your organisation and enforced at the database with row-level security — one tenant can never read another's data.

Data protection

Encrypted, isolated, minimised.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest. SSL is enforced on all database connections, and the application is served over HTTPS with strict security headers — HSTS, a content-security policy, and clickjacking protection.

Row-level isolation

Tenant separation is enforced in Postgres itself, not just in application code: every row is bound to an organisation and access is checked by row-level security policies on every read and write.

Pseudonymisation

Before any analysis, personal identifiers are replaced with a keyed, one-way (HMAC) token that is stable per organisation and not reversible — so the figures can be computed without exposing who is who.

k-anonymity

Every cohort carries a minimum-size floor. Groups too small to be safe are suppressed or rolled up into a larger one, so a published gap or survey result can never single out an individual.

AI & data minimisation

No personal data reaches the model.

AI is used only for narrow, well-scoped tasks (drafting report narratives and classifying roles) and every call passes through a single gateway with one job: keep personal data out.

One controlled path

All AI egress runs through a single server-side gateway — the only place model access is configured, logged and governed. No route talks to a model directly.

No identifiers sent

Prompts carry non-identifying attributes keyed to an ephemeral index; names, emails and IDs are removed structurally, with a redaction backstop catching any stray identifier before it can leave.

EU inference & choice

We are moving AI inference to EU-region processing, and intend to let each organisation choose its AI provider and data region — including an EU-sovereign option.

Hosting & access

Where it runs, and who can reach it.

EU hosting

Application and database run in EU regions, keeping personal data within the European Union.

Least privilege

Access within an organisation is role-based, and administrative access follows least-privilege principles. Multi-factor authentication and SSO are on our near-term roadmap.

Privacy-first analytics

Fonts are self-hosted. Any analytics we use are cookieless and aggregate — collecting no personal data, with no advertising or cross-site tracking, and nothing that identifies your visit.

Compliance & documentation

Doing due diligence?

Our processing is designed around the GDPR's Article 32 obligations on security of processing. For a deeper review, we can share our technical-and-organisational-measures summary, Data Processing Agreement and sub-processor list on request, along with our certification roadmap (including ISO 27001). A formal Trust Center will follow.

Security or compliance questions? Email security@paritir.com — including to report a vulnerability. We aim to acknowledge reports promptly and keep you updated through to resolution.

Compliance that respects the data.

See the whole workflow, end to end — no upload needed.