Browse all articles
Security
Each company gets a dedicated subdomain, so your data lives in its own isolated environment separate from other organizations. All personal data and documents are encrypted in transit and at rest, on servers hosted with Amazon Web Services. Visibility follows each user’s role and the permissions that role holds. Growee is GDPR compliant and has been independently penetration-tested and audited by Cyber Threat Defence.
Data isolation
When you create an account, Growee assigns your company a dedicated subdomain. Your data lives in its own isolated environment, completely separate from other organizations on the platform. There is no shared infrastructure that could expose your information to another account. The subdomain is set up automatically at account creation, with no technical work required on your end.
Encryption
All personal data and documents are encrypted, both in transit and at rest. Data moving between your devices and Growee’s servers is protected with industry-standard TLS, so it cannot be intercepted along the way. Growee’s servers are hosted on Amazon Web Services (AWS).
Role-based access
Visibility in Growee follows each user’s role and the permissions that role holds.
- Employee documents such as contracts and policies are visible to the roles that manage documents, which by default are Admin, Manager, and HR. By default, an employee can upload, view, and edit their own documents.
- Evaluations, including compensation and role changes, are visible to the roles that manage evaluations, which by default are Admin and Manager. A role granted the permission for subordinates sees the evaluations of the people below it in the reporting line. By default, an employee sees their own evaluations.
- Full employee profiles, including contract type, are visible to the roles that manage employees, which by default are Admin, Manager, and HR. Salary fields need a separate salary permission, which Admin holds by default. An employee sees their own profile and, for each colleague, a shorter profile with fields such as name, work email, phone number, birth date, photo, position, department, and start date.
- Invoices need the invoice permission, which Admin holds by default. Admin and Manager manage all projects, HR can view all of them, and an employee sees the projects they are assigned to.
- A custom role can be granted any of these permissions.
To learn how these roles map to specific abilities, see Roles and permissions.
Compliance and audits
Growee is GDPR compliant and PCI certified, meeting internationally recognized standards for data protection and payment security. The platform has been independently penetration-tested and audited by Cyber Threat Defence, a specialist cybersecurity firm, which awarded Growee a Certificate of Trust. Regular audits and continuous monitoring help keep your data safe as threats evolve. Where possible, data used for statistics and reporting is anonymized or pseudonymized so individuals cannot be identified from aggregated data.
Account and password security
Access to the app uses unique login credentials and role-based permissions. You can change your password from the Security section of your profile. If your account was created through a social login such as Google, your password is managed by that provider instead. In the unlikely event of a security incident, Growee follows established procedures to identify, contain, and mitigate it, and will notify affected customers and authorities where the law requires.
Related articles
Need more help? Contact support or email support@growee.net.