Security

Secure access, scoped data, and explicit operational boundaries.

HourLoop uses signed HTTP-only sessions, server-side bridge credentials, role checks, and generated MySQL/PHP contracts designed for scoped access.

Access control

Personal registration always creates an individual member account. Invitations determine organisation employee or manager access; platform administrators require protected provisioning.

Data handling

Private dashboard responses use no-store semantics. Bridge secrets stay server-side and sensitive backend errors are not returned to the browser.

Responsible disclosure

Report a suspected security issue privately to security@hourloop.co.za with steps to reproduce. Do not include real employee data.