Security

Your workforce data is sensitive. We treat it that way.

Employee skill profiles, HRIS data, and learning records are among the most sensitive data your organization holds. Succesvyx is designed from the ground up to handle this data responsibly — not as a compliance checkbox, but as an operating principle.

Security controls

Encryption at Rest and in Transit

All data stored in Succesvyx is encrypted at rest using AES-256. All data transmitted between your HRIS, your employees' browsers, and Succesvyx is encrypted using TLS 1.3. No plaintext storage of employee records.

Role-Based Access Control

Four permission levels: Employee (own data only), Manager (direct reports), L&D Admin (full organization), Executive (aggregate reports only, no individual data). No role can access data outside its defined scope.

Audit Logging

Every data access event, configuration change, and export action is logged with timestamp, user identity, and action details. Audit logs are immutable, retained for 24 months, and available for export on Enterprise plans.

Data Residency

All Succesvyx data is stored and processed within US-based infrastructure by default. Enterprise customers can request dedicated data residency agreements. Data is never replicated to non-contracted regions.

Compliance posture

Succesvyx is designed with SOC 2 Trust Services Criteria controls in mind across the Security, Availability, and Confidentiality categories. We have not yet completed a formal SOC 2 Type II audit — we are on that roadmap and will communicate completion publicly when it occurs. We do not claim SOC 2 certification at this time.

GDPR-Aware Data Handling

Data minimization, purpose limitation, and documented retention policies. Data Subject Access Requests processed within 30 days. Right to erasure honored within 7 days of request.

CCPA Data Rights

California Consumer Privacy Act rights honored for all users regardless of state. Right to know, right to delete, and right to opt out of sale (Succesvyx does not sell personal data) available via privacy request email.

Least-Privilege Access Controls

Internal Succesvyx team access to customer data follows least-privilege principles. Customer data access by Succesvyx personnel requires manager approval and is logged. Production access requires two-factor authentication.

Vendor Security Review

All third-party infrastructure vendors used by Succesvyx are reviewed for SOC 2 compliance or equivalent before contracting. Vendor list available to Enterprise customers under NDA.

Security review for enterprise evaluations

If your procurement team requires a security questionnaire, vendor risk assessment, or detailed data flow documentation, contact us. We provide a full security package within 5 business days.

Request Security Documentation