Security

We hold the payroll data of 1,200 companies. Here is exactly how we protect it.

Salaries, bank details, passport scans, tax IDs. The data an employer of record holds is the kind that cannot leak. This page is written for the person who has to sign off on us, with no sales call required to read it.

Last reviewed September 2026. Platform status: status page.

SOC 2 Type II

Annual audit, twelve-month observation period. Report under NDA.

ISO 27001

Certification in progress. Stage 2 audit scheduled for Q1 2027.

Encryption

AES-256 at rest. TLS 1.2 minimum in transit, TLS 1.3 preferred.

Hosting

AWS Ireland and Frankfurt. EU and UK data stays in region.

Certifications and audits

Audited by outsiders, twice a year by attackers

SOC 2 Type II. Ubique has held a SOC 2 Type II attestation since February 2024, covering the Security, Availability and Confidentiality trust criteria. The audit runs annually with a twelve-month observation period. The most recent report had no exceptions. Clients and prospects can request it under NDA from security@ubiquehq.co.uk; we send it within two business days.

ISO 27001. Certification is in progress. The information security management system is in place, the Stage 1 audit is complete, and the Stage 2 audit is scheduled for the first quarter of 2027. We will update this page the day the certificate is issued, and not before.

Penetration tests. An independent firm tests the platform, the API and the mobile web experience twice a year. Critical and high findings are fixed before the retest; a summary letter is available to clients on request.

What the SOC 2 report covers

The Ubique platform, API, payroll processing systems and the supporting infrastructure on AWS. It does not cover local employment partners, which are assessed separately under our partner programme.

Who tests us

A CREST-accredited UK firm for penetration testing, rotated every two years. A Big Four-affiliated audit firm for SOC 2.

Internal checks

Automated dependency scanning on every build, weekly infrastructure vulnerability scans, and quarterly access reviews signed off by the Head of Security.

Infrastructure and data

Where your data lives and how it is encrypted

EU

Hosting on AWS, Ireland and Frankfurt

Production runs in AWS eu-west-1 (Ireland) with replication to eu-central-1 (Frankfurt). Data for EU and UK clients and their employees never leaves these two regions. Clients outside the EU and UK are hosted in the same regions; we do not run a US region.

256

Encryption at rest

All databases, object storage and backups are encrypted with AES-256 using AWS KMS keys that Ubique controls. Bank details, tax identifiers and identity documents are additionally encrypted at the field level with keys separate from the database keys.

TLS

Encryption in transit

TLS 1.2 is the minimum for every connection, including the API and integrations. TLS 1.3 is preferred and negotiated by default. HSTS is enforced. Internal service-to-service traffic is also encrypted.

B

Backups

Point-in-time recovery for the last 35 days. Daily encrypted snapshots held in Frankfurt for 12 months. Restores are tested quarterly, and the result is recorded in the SOC 2 evidence.

S

Separation

Every client's data is logically separated by tenant ID at the application and database layer. Production, staging and development environments are separate AWS accounts with no shared credentials.

L

Logging

Every access to personal data is logged with who, what and when, and retained for 12 months. Logs are immutable and monitored for unusual patterns such as bulk exports or out-of-hours access.

Access control

MFA is not optional. For anyone.

Every user on the Ubique platform, whether a client administrator, an employee checking a payslip or a Ubique employee in support, must use multi-factor authentication. There is no setting to turn it off.

  • Mandatory MFA with authenticator apps or hardware keys. SMS is not offered.
  • Single sign-on with Okta, Google Workspace or any SAML 2.0 identity provider. SCIM provisioning deprovisions users when they leave your directory.
  • Role-based access control with built-in roles (owner, admin, finance, People, manager, viewer) and custom roles scoped by country, team or data type.
  • Least privilege inside Ubique. Support staff see only the accounts they are assigned to, and only after the client has enabled support access. Payroll data is visible only to the payroll team for that country.
  • Session controls. Configurable session length, device listing, and remote sign-out for administrators.

Background checks

Every Ubique employee with access to production or client data passes a background check appropriate to their country before access is granted.

Security training

Mandatory at onboarding and every year, with phishing simulations each quarter. Engineers get secure coding training on top.

Device management

Company laptops are managed, encrypted and monitored. Personal devices cannot access production systems.

Privacy and compliance

GDPR, UK Data Protection Act 2018 and CCPA

Ubique Group Limited is registered with the UK Information Commissioner's Office and has an appointed Data Protection Officer. The DPA is a standard document. You can read it before you ever talk to sales.

Data Processing Agreement

Our DPA covers roles, subprocessors, security measures, breach notification within 48 hours, audit rights and international transfers under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

Read the DPA

Privacy policy

What we collect from clients, the people we employ, contractors and website visitors, the lawful bases, retention periods and your rights. Only essential cookies are set on this site.

Read the privacy policy

Data subject requests

Access, correction, deletion and portability requests go to privacy@ubiquehq.co.uk. We acknowledge within two business days and resolve within one month, with one caveat: employment records we must keep by law are retained for the statutory period.

Subprocessors

Who else touches the data

We keep the list short on purpose. Clients are notified by email 30 days before a subprocessor is added, with the right to object under the DPA.

SubprocessorPurposeLocationData
Amazon Web ServicesHosting, storage, backupsIreland, FrankfurtAll platform data, encrypted
Local employment and payroll partnersEmployment and payroll in the 120 partner-served countriesThe employee's countryEmployment and payroll data for the team members they employ. Full list by country in your dashboard.
E-signature providerContract signatureEUContract documents, signer name and email
Transactional email providerNotifications, payslip alerts, invitationsEUName, email, notification content
Payment and FX providersSalary and contractor payments in 100 currenciesUK, EUPayee name, bank details, amounts

Benefits brokers and immigration partners are engaged only when you buy the corresponding add-on, and are listed in the order form for that service.

Incident response

What happens when something goes wrong

We have an incident response plan, an on-call rotation across three time zones, and a rule that the client hears from us before they hear from anyone else.

Detect and triage, within 1 hour

Automated alerting and 24/7 on-call. The incident lead classifies severity and opens a status page entry for anything client-facing.

Contain and assess

Isolate affected systems, preserve evidence, establish what data is involved and whose. The Head of Security and the DPO are paged for any suspected personal data breach.

Notify, within 48 hours

Affected clients are notified within 48 hours of confirming a personal data breach, with what happened, what data, what we have done and what you need to do. Regulators are notified where required within 72 hours.

Review and publish

A blameless post-incident review within 10 business days, shared with affected clients. Service-affecting incidents get a public write-up on the status page.

Availability

99.9% monthly uptime target for the platform and API, excluding announced maintenance. Enterprise contracts carry an SLA with credits. Live and historical uptime is on the status page.

Business continuity

Multi-availability-zone deployment with regional failover to Frankfurt. Recovery time objective 4 hours, recovery point objective 15 minutes. Payroll runs have a manual fallback so people get paid even during an outage.

Payday protection

Salary funding is held in segregated client accounts at a UK-regulated institution. A security incident cannot stop a payroll that has already been funded.

Responsible disclosure

Found something? Tell us, and we will not come after you.

We welcome reports from security researchers. Email security@ubiquehq.co.uk with the steps to reproduce, the affected URL or endpoint and, if you like, how you would like to be credited. PGP key available on request.

What we promise

  • Acknowledgement within 2 business days and a severity assessment within 5.
  • A fix timeline: critical within 7 days, high within 30, medium and low within 90.
  • Credit on this page if you want it, and a thank-you that is not just an email.

Safe harbour

If you follow these terms, Ubique will not pursue legal action against you for your research, will not report you to law enforcement, and will consider your research authorised under the Computer Misuse Act 1990 and equivalent laws.

  • Test only against accounts you own or have created for testing. Never access another person's data; if you reach it by accident, stop and tell us.
  • No denial of service, social engineering of Ubique staff or clients, physical attacks, or testing of our partners' or subprocessors' systems.
  • Do not download, modify or delete data beyond what is needed to demonstrate the issue.
  • Give us 90 days before public disclosure, or until the fix ships, whichever is sooner. We will coordinate the date with you.

Out of scope: findings on third-party services, missing best-practice headers with no demonstrated impact, and reports from automated scanners without a working proof of concept.

Need a security questionnaire filled in?

Send it to security@ubiquehq.co.uk. Standard questionnaires come back within five business days, with the SOC 2 report attached under NDA.