Security
Secure access, scoped data, and explicit operational boundaries.
HourLoop uses signed HTTP-only sessions, server-side bridge credentials, role checks, and generated MySQL/PHP contracts designed for scoped access.
Access control
Personal registration always creates an individual member account. Invitations determine organisation employee or manager access; platform administrators require protected provisioning.
Data handling
Private dashboard responses use no-store semantics. Bridge secrets stay server-side and sensitive backend errors are not returned to the browser.
Responsible disclosure
Report a suspected security issue privately to security@hourloop.co.za with steps to reproduce. Do not include real employee data.
