Security & privacy
Built for the most sensitive data you hold.
Paritir processes pay, gender and role data to help you meet the EU Pay Transparency Directive — so privacy and security aren't a feature, they're the foundation. Here's how we protect it: in plain language, and accurate to how the platform actually works.
Minimise, then protect
We collect only what the obligation needs, pseudonymise personal identifiers before analysis, and never surface an individual. Privacy is engineered into each step, not bolted on.
Hosted in the EU, one exception named
Application, database, email and error monitoring run in EU regions. One sub-processor, for AI inference, is in the United States; the transfer is protected by the EU–US Data Privacy Framework and its UK Extension where the provider is certified, or otherwise by Standard Contractual Clauses; what reaches it is minimised to what each task needs, as the data processing agreement sets out. We are moving model inference to EU-region processing.
Your data is only yours
Every query is scoped to your organisation and enforced at the database with row-level security — one tenant can never read another's data.
Data protection
Encrypted, isolated, minimised
Encryption everywhere
Data is encrypted in transit (TLS) and at rest. SSL is enforced on all database connections, and the application is served over HTTPS with strict security headers — HSTS, a content-security policy, and clickjacking protection.
Row-level isolation
Tenant separation is enforced in Postgres itself, not just in application code: every row is bound to an organisation and access is checked by row-level security policies on every read and write.
Pseudonymisation
Before any analysis, personal identifiers are replaced with a keyed, one-way token (HMAC, a keyed hash) that is stable per organisation and not reversible — so the figures can be computed without exposing who is who.
k-anonymity (minimum group size)
Every cohort carries a minimum-size floor. Groups too small to be safe are suppressed or rolled up into a larger one, so a published gap or survey result can never single out an individual.
AI & data minimisation
The model gets only what the task needs
AI drafts report narratives, classifies roles and job data, translates, and answers questions in the in-product assistant. Every call passes through a single server-side gateway, and every request is cut down to what its task needs.
One controlled path
All AI egress runs through a single server-side gateway — the only place model access is configured, logged and governed. No route talks to a model directly.
Minimised by design
Reports and classifications are built from non-identifying attributes keyed to an ephemeral index, so names, emails and IDs are never part of the request. Some features work on text people write or upload: assistant questions, interview transcripts, documents, and survey text for translation. That text is sent as written, with email addresses removed, because a question stripped of its content can't be answered.
Provider and region
We are moving model inference to EU-region processing, and intend to let each organisation choose its AI provider and data region, including an EU-sovereign option. Today's provider is listed in the data processing agreement.
Hosting & access
Where it runs, and who can reach it
EU hosting
Application and database run in EU regions. The sub-processor list, including the one US provider, is in the data processing agreement.
Least privilege
Access within an organisation is role-based; a legal-reviewer role approves reports without seeing personal data; every API endpoint declares who may call it, and CI rejects one that doesn't.
Privacy-first analytics
Fonts are self-hosted. Any analytics we use are cookieless and aggregate — collecting no personal data, with no advertising or cross-site tracking, and nothing that identifies your visit.
Access you can audit
Who sees what, and how it is enforced
Small groups
Small groups are suppressed using the minimum national law sets for that country and disclosure route, and a cautious default where none is set.
Legal review
A legal-reviewer role reviews and approves pay reports without seeing personal data.
API access
Every API endpoint must declare who may call it; CI rejects one that doesn't.
Compliance & documentation
Doing due diligence?
Our processing is designed around the GDPR's Article 32 obligations on security of processing. For a deeper review, we can share our technical-and-organisational-measures summary, Data Processing Agreement and sub-processor list on request, along with our roadmap: ISO 27001 certification, multi-factor authentication and single sign-on. A formal Trust Center will follow.
Security or compliance questions? Email security@paritir.com — including to report a vulnerability. We aim to acknowledge reports promptly and keep you updated through to resolution.
Compliance that respects the data
See the whole workflow in a short guided tour, then apply to run it on your own data.