Security & Trust

People get paid based on what Attendify records.
We treat it that way.

Attendance data decides salaries, overtime, and disputes. This page explains, plainly, how we protect it, how we verify it, and how it stays yours.

GCC

Data hosted in-region

TLS

Encrypted in transit and at rest

OTP + JWT

Phone-verified authentication

100%

Sensitive actions audit-logged

1:1

One isolated tenant per company

Data protection

Aligned with Kuwait CITRA and GCC data-protection law

Attendify is designed to operate in line with Kuwait's CITRA Resolution No. 26 of 2024 and comparable data-protection regulations across the GCC. We say aligned because that is the honest word: we follow the rules, and we do not claim certifications we do not hold.

Kuwait CITRA alignment

Built in line with CITRA Resolution No. 26 of 2024 on data privacy protection, and comparable GCC regulations.

DPA available on request

Need a Data Processing Agreement for procurement or legal review? Ask, and we will send it.

The data stays yours

Your attendance records belong to your company. We process them on your behalf, nothing more.

Export anytime

Pull your data out in bulk whenever you want. No tickets, no waiting, no lock-in.

Security architecture

Access is narrow by design

Fewer people seeing less data, verified more often. That is the whole idea.

Role-based access control

Five roles: super admin, admin, HR, supervisor, and employee. Each role sees what it needs for the job, nothing more.

Per-company tenant isolation

Every company runs in its own isolated tenant. Your records are never mixed with another customer's.

Device binding

One employee, one registered device. A check-in from an unrecognized phone is refused until an admin approves the change.

Rate-limited OTP login

Login codes are sent to the employee's phone and rate-limited against brute-force attempts. No passwords to leak or reuse.

Who sees what

Super admin

Platform administration

Admin

Company-wide settings & reports

HR

Attendance, leave & payroll data

Supervisor

Their team only

Employee

Their own records only

Record integrity

Five checks between a tap and a payroll record

Every check-in is validated on the server before it counts. Fail a check, and the record is rejected or flagged for review.

  1. Server-side timestamp validation

    The server clock decides the time, not the phone. If a device clock drifts more than 10 minutes from the server, the check-in is rejected.

  2. GPS-spoof detection

    Mock-location apps and GPS spoofing are detected, and the check-in is blocked before a fake location is accepted.

  3. Geofence validation

    The reported location is checked against your branch geofence. Outside the zone means no check-in.

  4. Photo capture at check-in

    A photo is taken at check-in, so every name on a report has a face behind it.

  5. Private face templates

    Face verification templates are stored privately, used only to verify your own employees, and never shared or sold.

Your data, your control

Your records, on your terms

The data was always yours. These are the controls that keep it that way.

Retention that follows your policy

Attendance history is kept for as long as you need it and your policy requires, not a day longer than you want.

Deletion on request

Ask us to delete your company's data and we delete it, completely.

Bulk export

Download your records in bulk at any time, for your accountant, your auditor, or your archive.

Minimal subprocessors

We keep third parties to the minimum the service needs: SMS delivery and cloud hosting. Nobody else touches your data.

Security FAQ

The questions procurement asks

On cloud infrastructure in the GCC region. Your attendance data stays close to home, inside a legal environment your lawyers already know.

Only the roles you authorize, such as admins and HR. Location is captured at check-in and check-out, and during active work sessions according to your company policy. It is not continuous personal tracking, and nothing is recorded outside of that.

Yes. A DPA is available on request for procurement and legal review. Contact us and we will send the current version.

You export everything in bulk, then we delete your company's data on request. No lock-in, and no copies kept against your wishes.

Have a security questionnaire?

Send it over. We answer procurement and IT security reviews quickly and honestly. And if you are still comparing us with wall-mounted machines, we wrote that up too.