Your workforce data is sensitive. We treat it that way.
Employee skill profiles, HRIS data, and learning records are among the most sensitive data your organization holds. Succesvyx is designed from the ground up to handle this data responsibly — not as a compliance checkbox, but as an operating principle.
Security controls
Encryption at Rest and in Transit
All data stored in Succesvyx is encrypted at rest using AES-256. All data transmitted between your HRIS, your employees' browsers, and Succesvyx is encrypted using TLS 1.3. No plaintext storage of employee records.
Role-Based Access Control
Four permission levels: Employee (own data only), Manager (direct reports), L&D Admin (full organization), Executive (aggregate reports only, no individual data). No role can access data outside its defined scope.
Audit Logging
Every data access event, configuration change, and export action is logged with timestamp, user identity, and action details. Audit logs are immutable, retained for 24 months, and available for export on Enterprise plans.
Data Residency
All Succesvyx data is stored and processed within US-based infrastructure by default. Enterprise customers can request dedicated data residency agreements. Data is never replicated to non-contracted regions.
Compliance posture
Succesvyx is designed with SOC 2 Trust Services Criteria controls in mind across the Security, Availability, and Confidentiality categories. We have not yet completed a formal SOC 2 Type II audit — we are on that roadmap and will communicate completion publicly when it occurs. We do not claim SOC 2 certification at this time.
GDPR-Aware Data Handling
Data minimization, purpose limitation, and documented retention policies. Data Subject Access Requests processed within 30 days. Right to erasure honored within 7 days of request.
CCPA Data Rights
California Consumer Privacy Act rights honored for all users regardless of state. Right to know, right to delete, and right to opt out of sale (Succesvyx does not sell personal data) available via privacy request email.
Least-Privilege Access Controls
Internal Succesvyx team access to customer data follows least-privilege principles. Customer data access by Succesvyx personnel requires manager approval and is logged. Production access requires two-factor authentication.
Vendor Security Review
All third-party infrastructure vendors used by Succesvyx are reviewed for SOC 2 compliance or equivalent before contracting. Vendor list available to Enterprise customers under NDA.