We hold the payroll data of 1,200 companies. Here is exactly how we protect it.
Salaries, bank details, passport scans, tax IDs. The data an employer of record holds is the kind that cannot leak. This page is written for the person who has to sign off on us, with no sales call required to read it.
Last reviewed September 2026. Platform status: status page.
SOC 2 Type II
Annual audit, twelve-month observation period. Report under NDA.
ISO 27001
Certification in progress. Stage 2 audit scheduled for Q1 2027.
Encryption
AES-256 at rest. TLS 1.2 minimum in transit, TLS 1.3 preferred.
Hosting
AWS Ireland and Frankfurt. EU and UK data stays in region.
Audited by outsiders, twice a year by attackers
SOC 2 Type II. Ubique has held a SOC 2 Type II attestation since February 2024, covering the Security, Availability and Confidentiality trust criteria. The audit runs annually with a twelve-month observation period. The most recent report had no exceptions. Clients and prospects can request it under NDA from security@ubiquehq.co.uk; we send it within two business days.
ISO 27001. Certification is in progress. The information security management system is in place, the Stage 1 audit is complete, and the Stage 2 audit is scheduled for the first quarter of 2027. We will update this page the day the certificate is issued, and not before.
Penetration tests. An independent firm tests the platform, the API and the mobile web experience twice a year. Critical and high findings are fixed before the retest; a summary letter is available to clients on request.
What the SOC 2 report covers
The Ubique platform, API, payroll processing systems and the supporting infrastructure on AWS. It does not cover local employment partners, which are assessed separately under our partner programme.
Who tests us
A CREST-accredited UK firm for penetration testing, rotated every two years. A Big Four-affiliated audit firm for SOC 2.
Internal checks
Automated dependency scanning on every build, weekly infrastructure vulnerability scans, and quarterly access reviews signed off by the Head of Security.
Where your data lives and how it is encrypted
Hosting on AWS, Ireland and Frankfurt
Production runs in AWS eu-west-1 (Ireland) with replication to eu-central-1 (Frankfurt). Data for EU and UK clients and their employees never leaves these two regions. Clients outside the EU and UK are hosted in the same regions; we do not run a US region.
Encryption at rest
All databases, object storage and backups are encrypted with AES-256 using AWS KMS keys that Ubique controls. Bank details, tax identifiers and identity documents are additionally encrypted at the field level with keys separate from the database keys.
Encryption in transit
TLS 1.2 is the minimum for every connection, including the API and integrations. TLS 1.3 is preferred and negotiated by default. HSTS is enforced. Internal service-to-service traffic is also encrypted.
Backups
Point-in-time recovery for the last 35 days. Daily encrypted snapshots held in Frankfurt for 12 months. Restores are tested quarterly, and the result is recorded in the SOC 2 evidence.
Separation
Every client's data is logically separated by tenant ID at the application and database layer. Production, staging and development environments are separate AWS accounts with no shared credentials.
Logging
Every access to personal data is logged with who, what and when, and retained for 12 months. Logs are immutable and monitored for unusual patterns such as bulk exports or out-of-hours access.
MFA is not optional. For anyone.
Every user on the Ubique platform, whether a client administrator, an employee checking a payslip or a Ubique employee in support, must use multi-factor authentication. There is no setting to turn it off.
- Mandatory MFA with authenticator apps or hardware keys. SMS is not offered.
- Single sign-on with Okta, Google Workspace or any SAML 2.0 identity provider. SCIM provisioning deprovisions users when they leave your directory.
- Role-based access control with built-in roles (owner, admin, finance, People, manager, viewer) and custom roles scoped by country, team or data type.
- Least privilege inside Ubique. Support staff see only the accounts they are assigned to, and only after the client has enabled support access. Payroll data is visible only to the payroll team for that country.
- Session controls. Configurable session length, device listing, and remote sign-out for administrators.
Background checks
Every Ubique employee with access to production or client data passes a background check appropriate to their country before access is granted.
Security training
Mandatory at onboarding and every year, with phishing simulations each quarter. Engineers get secure coding training on top.
Device management
Company laptops are managed, encrypted and monitored. Personal devices cannot access production systems.
GDPR, UK Data Protection Act 2018 and CCPA
Ubique Group Limited is registered with the UK Information Commissioner's Office and has an appointed Data Protection Officer. The DPA is a standard document. You can read it before you ever talk to sales.
Data Processing Agreement
Our DPA covers roles, subprocessors, security measures, breach notification within 48 hours, audit rights and international transfers under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
Privacy policy
What we collect from clients, the people we employ, contractors and website visitors, the lawful bases, retention periods and your rights. Only essential cookies are set on this site.
Data subject requests
Access, correction, deletion and portability requests go to privacy@ubiquehq.co.uk. We acknowledge within two business days and resolve within one month, with one caveat: employment records we must keep by law are retained for the statutory period.
Who else touches the data
We keep the list short on purpose. Clients are notified by email 30 days before a subprocessor is added, with the right to object under the DPA.
| Subprocessor | Purpose | Location | Data |
|---|---|---|---|
| Amazon Web Services | Hosting, storage, backups | Ireland, Frankfurt | All platform data, encrypted |
| Local employment and payroll partners | Employment and payroll in the 120 partner-served countries | The employee's country | Employment and payroll data for the team members they employ. Full list by country in your dashboard. |
| E-signature provider | Contract signature | EU | Contract documents, signer name and email |
| Transactional email provider | Notifications, payslip alerts, invitations | EU | Name, email, notification content |
| Payment and FX providers | Salary and contractor payments in 100 currencies | UK, EU | Payee name, bank details, amounts |
Benefits brokers and immigration partners are engaged only when you buy the corresponding add-on, and are listed in the order form for that service.
What happens when something goes wrong
We have an incident response plan, an on-call rotation across three time zones, and a rule that the client hears from us before they hear from anyone else.
Detect and triage, within 1 hour
Automated alerting and 24/7 on-call. The incident lead classifies severity and opens a status page entry for anything client-facing.
Contain and assess
Isolate affected systems, preserve evidence, establish what data is involved and whose. The Head of Security and the DPO are paged for any suspected personal data breach.
Notify, within 48 hours
Affected clients are notified within 48 hours of confirming a personal data breach, with what happened, what data, what we have done and what you need to do. Regulators are notified where required within 72 hours.
Review and publish
A blameless post-incident review within 10 business days, shared with affected clients. Service-affecting incidents get a public write-up on the status page.
Availability
99.9% monthly uptime target for the platform and API, excluding announced maintenance. Enterprise contracts carry an SLA with credits. Live and historical uptime is on the status page.
Business continuity
Multi-availability-zone deployment with regional failover to Frankfurt. Recovery time objective 4 hours, recovery point objective 15 minutes. Payroll runs have a manual fallback so people get paid even during an outage.
Payday protection
Salary funding is held in segregated client accounts at a UK-regulated institution. A security incident cannot stop a payroll that has already been funded.
Found something? Tell us, and we will not come after you.
We welcome reports from security researchers. Email security@ubiquehq.co.uk with the steps to reproduce, the affected URL or endpoint and, if you like, how you would like to be credited. PGP key available on request.
What we promise
- Acknowledgement within 2 business days and a severity assessment within 5.
- A fix timeline: critical within 7 days, high within 30, medium and low within 90.
- Credit on this page if you want it, and a thank-you that is not just an email.
Safe harbour
If you follow these terms, Ubique will not pursue legal action against you for your research, will not report you to law enforcement, and will consider your research authorised under the Computer Misuse Act 1990 and equivalent laws.
- Test only against accounts you own or have created for testing. Never access another person's data; if you reach it by accident, stop and tell us.
- No denial of service, social engineering of Ubique staff or clients, physical attacks, or testing of our partners' or subprocessors' systems.
- Do not download, modify or delete data beyond what is needed to demonstrate the issue.
- Give us 90 days before public disclosure, or until the fix ships, whichever is sooner. We will coordinate the date with you.
Out of scope: findings on third-party services, missing best-practice headers with no demonstrated impact, and reports from automated scanners without a working proof of concept.
Need a security questionnaire filled in?
Send it to security@ubiquehq.co.uk. Standard questionnaires come back within five business days, with the SOC 2 report attached under NDA.