Security & compliance you can trust
Built multi-tenant from day one, with biometric privacy and an immutable audit trail.
Tenant isolation
Strict role- and location-based access (RBAC + ABAC) so each company and store sees only its own data.
Encryption
Encrypted at rest and in transit, with field-level encryption for sensitive PII.
Biometric privacy
Face embeddings only — never raw images — with consent and deletion (BIPA / CCPA).
Audit logging
Every sensitive action is recorded immutably for compliance and disputes.
Labor compliance
FLSA plus state overtime, meal-break and minor-work rules built into the engine.
Compliance roadmap
SOC 2, GDPR and CCPA on the roadmap as we scale.
Frequently asked questions
How does ClockAll protect biometric data?
Face verification stores only an encrypted mathematical embedding — never a photo or image of a face — collected with written notice and consent, and destroyed under a written retention policy. That’s how it aligns with BIPA and CCPA.
Is my data encrypted?
Yes — encrypted in transit and at rest, with field-level encryption for sensitive personal information.
Who can see my company’s data?
Access is strictly role- and location-based (RBAC + ABAC), so each company and store sees only its own data, and every sensitive action is logged in an immutable audit trail.
Is ClockAll SOC 2 or GDPR compliant?
SOC 2, GDPR and CCPA are on our compliance roadmap as we scale. The platform is built multi-tenant with encryption, access controls, and audit logging from day one.
Security that earns your team’s trust
Try it on your own team — free forever for teams up to 3, no card required.