Security & compliance you can trust

Built multi-tenant from day one, with biometric privacy and an immutable audit trail.

Tenant isolation

Strict role- and location-based access (RBAC + ABAC) so each company and store sees only its own data.

Encryption

Encrypted at rest and in transit, with field-level encryption for sensitive PII.

Biometric privacy

Face embeddings only — never raw images — with consent and deletion (BIPA / CCPA).

Audit logging

Every sensitive action is recorded immutably for compliance and disputes.

Labor compliance

FLSA plus state overtime, meal-break and minor-work rules built into the engine.

Compliance roadmap

SOC 2, GDPR and CCPA on the roadmap as we scale.

Frequently asked questions

How does ClockAll protect biometric data?

Face verification stores only an encrypted mathematical embedding — never a photo or image of a face — collected with written notice and consent, and destroyed under a written retention policy. That’s how it aligns with BIPA and CCPA.

Is my data encrypted?

Yes — encrypted in transit and at rest, with field-level encryption for sensitive personal information.

Who can see my company’s data?

Access is strictly role- and location-based (RBAC + ABAC), so each company and store sees only its own data, and every sensitive action is logged in an immutable audit trail.

Is ClockAll SOC 2 or GDPR compliant?

SOC 2, GDPR and CCPA are on our compliance roadmap as we scale. The platform is built multi-tenant with encryption, access controls, and audit logging from day one.

Security that earns your team’s trust

Try it on your own team — free forever for teams up to 3, no card required.