Security is a design constraint in Staffvelo, not a feature. Here is what we do, in plain terms.
Architecture
- The application runs on Cloudflare Workers at the network edge, behind Cloudflare's DDoS protection and WAF.
- Data is stored in Cloudflare D1 (database) and R2 (uploaded files), encrypted at rest.
- All traffic is served over HTTPS with modern TLS.
Tenant isolation
Each company has its own workspace at company.staffvelo.com. Every database row carries the company identifier and every query is scoped to it; a workspace can never read another workspace's records. Requests to a subdomain that isn't a workspace are refused rather than falling back to another company.
Authentication and access
- Passwords are hashed with bcrypt. Invitations and password links are single-use tokens.
- Sessions are signed, HttpOnly, Secure cookies with a seven-day lifetime.
- Sign-in is throttled: repeated wrong passwords lock an email address for 15 minutes, and sign-up, demo-booking and newsletter forms are rate-limited per IP.
- Optional Google sign-in (OpenID Connect) on every plan.
- Three access levels plus manager scoping, enforced on the server for every request — not just hidden in the interface.
Application security
Strict Content-Security-Policy, HSTS, clickjacking protection (X-Frame-Options), a strict Referrer-Policy and Permissions-Policy on every response; output encoding everywhere, parameterised queries throughout, file-type and size limits on uploads. Payment details go straight to Stripe and never touch our servers.
Privacy tooling built in
- Export: every person can download everything the workspace holds about them as JSON from their profile; admins can export any profile for a subject-access request.
- Erasure: when someone has left, an admin can erase their personal data in one step — the record is anonymised and behavioural data deleted, while payslips and expense records are kept for the statutory period against an anonymous "Former employee".
- Workspace deletion: a Super Admin can delete the whole workspace from Settings; every record and file is removed immediately and any subscription is cancelled.
- Automatic retention: notifications and sent email are purged after 12 months, sign-in attempt logs after 2 days, billing and activity logs after 24 months.
Email
Transactional email is sent via Resend from a domain authenticated with DKIM, SPF and DMARC.
Backups and continuity
The database keeps point-in-time recovery for 30 days. Uploaded files are copied every night to a second storage bucket in a different European region. When a workspace is deleted, its data is removed from live systems immediately and ages out of point-in-time recovery and the file copy within 30 days.
Reporting a vulnerability
Please email security@staffvelo.com. We acknowledge reports within two working days, keep you informed, and don't take action against good-faith research.