Security and Trust
SOC 2 Type II certified, 99.9% uptime, and the detail behind both
Employee data is the most sensitive data your organization holds, and employee relations casework is the most sensitive part of that. Here is the posture, stated plainly, before you send the questionnaire.
SOC 2
Type II AICPA certification
For the Dovetail HR SaaS product, alongside EU-U.S. with UK Extension and Swiss-U.S. Data Privacy Framework certification.
99.9%
Uptime for HR operations
Hosted on AWS across physically separate availability zones with real-time cross-region replication.
1M+
Security events monitored annually
Continuous monitoring with alerting to key personnel, plus regular third-party penetration testing.
Certifications and attestations
Independently assessed, not self declared
Every certification below can be checked without asking us. Our Data Privacy Framework entry is listed Active for HR and non-HR data under all three frameworks on the U.S. Department of Commerce register: search it for Dovetail Software.
AICPA SOC 2 Type II
Achieved for the Dovetail HR SaaS product. Report available under NDA.
SOC 2 Type II
Data Privacy Framework
Certified under the EU-U.S. Data Privacy Framework including the UK Extension, and the Swiss-U.S. Data Privacy Framework.
EU-U.S. / UK / Swiss
Penetration testing
Dovetail works with third-party experts for regular penetration testing, systematically uncovering and addressing vulnerabilities.
Third party
EU GDPR
Compliant with EU GDPR and US data privacy protection laws and regulations, with third-party providers held to the same standards.
GDPR
Controls in place
How the data is actually protected
Encryption at rest
AES-256, with keys held in AWS Key Management Service and rotated automatically, so no one is managing key lifecycle by hand.
AES-256 + AWS KMS
Encryption in transit
TLS 1.2 or 1.3 for HTTP and SSH for SFTP. Optional PGP encryption for SFTP file transfers.
TLS 1.2 / 1.3
Authentication
SAML v2 single sign-on with multi-factor authentication, preventing login sharing and session hijacking.
SAML v2 + MFA
Authorization
Role-based access control, with access rights adjusted dynamically as the organization changes.
Role based
Monitoring
Over one million security events monitored annually, with alerting to key personnel for prompt response.
1M+ events/yr
Continuity
Backup strategies and disaster recovery processes designed for rapid recovery, including from ransomware.
DR and backup
Build and run
How the software is built, patched and watched
Everything below is documented. The SOC 2 Type II report, the cybersecurity whitepaper and the current penetration test summary are in the Trust Center.
Secure development
OWASP and SANS guidance is built into the development process, so the common vulnerability classes are handled before code ships rather than found in a test afterwards.
OWASP and SANS
Patching
Servers are rebuilt monthly on the latest security patches. Where components are serverless there is no host to patch or to compromise.
Monthly rebuild
Threat detection
AWS Security Hub, GuardDuty and CloudTrail monitor for anomalous activity. Security logs are retained and readable only by named personnel.
AWS SIEM
Recovery
Off-site backups and documented disaster recovery, with recovery simulations run regularly rather than assumed to work.
Tested, not assumed
Threat coverage
The four your questionnaire will name
Employee data is a target because it is complete: identity, contact, pay, health and grievance detail in one place. These are the specific answers, not a posture statement.
Ransomware
HR data sits in AWS, not on your corporate network, so a ransomware event on your estate does not reach your case records. Off-site backups and real-time detection sit behind that.
Off network
Phishing
SSO with MFA means there is no Dovetail password to phish, and authentication policy, geo-fencing included, stays under your control rather than ours.
No local password
Stolen sessions
Session length limits cap how long a hijacked session or a keylogged credential stays useful, on top of SSO and MFA.
Session limits
Persistence
Restricted access policies, regular system scans and the monthly server rebuild remove persistence. Serverless components leave nothing to persist on.
Nothing to sit on
Data residency
You choose the region, and it stays there
Our hosting facilities are aligned with data residency in mind. You specify whether your data is hosted in our US or European data centers, and it will reside there even in a situation where a back-up hosting facility is required.
- Customer choice of US or European data centers
- Data remains in the designated region, including during failover
- Physically separate AWS availability zones within your region
- Customer-configurable retention schedules
Employee relations data
The most sensitive records you will hold
ER casework carries confidentiality obligations that general HR case data does not. These controls are specific to it.
Case level restriction
Visibility controlled at case, category and team level, entirely separately from general HR case management.
Restricted
Audit integrity
Hiding a note changes its visibility, not its presence in the audit record.
Immutable record
Retention by policy
Customers can establish retention schedules rather than accepting a vendor default, and place a legal hold so a record is exempted from purge while a matter is live.
Configurable
Privacy tooling
Subject access, retention and erasure support for employee data under GDPR.
GDPR tooling
HIPAA and PHI
Why we do not sign a Business Associate Agreement, and what we do instead
Healthcare buyers ask for a BAA early, often in the first call. Our answer is no, and the reason is worth reading, because it is the same reason your own counsel will give you once they look at it.
HIPAA excludes employment records from protected health information. 45 CFR 160.103 says that individually identifiable health information in employment records held by a covered entity in its role as an employer is not PHI. HHS guidance says the same. So a doctor's note attached to an FMLA request, an accommodation letter, or a fitness for duty certificate is an employment record in your HR system, not PHI. That holds even when you are a hospital or a health plan, because you are receiving it as the employer, not as the provider.
Dovetail is not a business associate. On the definition in the same regulation, a business associate creates, receives, maintains or transmits PHI on behalf of a covered entity, or performs claims processing, data analysis, utilization review or billing. We do none of those. Dovetail is HR case management software. It is not a medical record system and it is not part of your healthcare operations.
Signing one anyway is not the safe option, it is the sloppy one. A BAA where none is required accepts HIPAA obligations that do not attach to what the product does, and it tells your own auditors that PHI is being processed in a system that is not designed to hold it. We would rather have this conversation once, in writing, than sign a document that misdescribes both of us.
What we sign instead. A Data Protection Agreement. It covers the same ground a security team actually cares about, processing terms, security obligations, breach handling and sub-processors, without categorizing Dovetail as something it is not.
The case where the answer changes. If an on-site clinic operates as a covered healthcare provider in its own right and its patient records would be stored in Dovetail, that is PHI and a BAA would be required. That is not what the product is for, and we would tell you so rather than take the deal.
This is our position, not legal advice. Your counsel should reach their own view, and in our experience they usually reach this one.
The laws that do apply
ADA, FMLA and GINA ask for something HIPAA does not, and it is a product requirement
Employee medical information is still confidential, it is just confidential under different law. The ADA requires it to be kept separately from the general personnel file and released on a need to know basis. FMLA and GINA carry their own restrictions.
That is a system requirement, not a filing instruction, and it is the part most HR tools fail. A leave certificate sitting in a case anyone in HR can open does not meet it, whatever the vendor signed.
- Sensitive case flag, so a leave or accommodation case is separated from general HR volume
- Employee filters, case labels, organization, department and queue restrictions, applied independently
- Reporting and notifications honor the same restrictions, so a restricted case does not surface in a scheduled export
- Retention schedules you set, with legal hold when a matter is live
Common questions
Will you sign a Business Associate Agreement?
No, and the reason is that HIPAA does not apply to what Dovetail does. Under 45 CFR 160.103, health information in employment records held by a covered entity in its role as an employer is not protected health information. Dovetail does not create, receive, maintain or transmit PHI on behalf of a covered entity, and does not perform claims processing, billing or medical record analysis, so it is not a business associate. We sign a Data Protection Agreement instead, which covers the same security ground without miscategorizing either party. The exception is an on-site clinic operating as a covered provider in its own right, where patient records would be PHI and Dovetail is not the right system.
An employee uploaded a medical certificate for FMLA. Is that PHI?
No. Once health information is given by an employee to their employer for an employment purpose, it becomes an employment record rather than PHI, and HIPAA protections do not follow it. HHS guidance and the case law both say so. It is still confidential, but under the ADA, FMLA and GINA rather than HIPAA, and those laws require it to be kept separate from the general personnel file and released on a need to know basis. The case restriction model is built for exactly that.
We are a hospital. Does that change the answer?
Not for HR casework. A covered entity is covered in its role as a healthcare provider, not in its role as an employer. The employment records exclusion is explicit in the regulation and HHS has restated it, including in its COVID workplace guidance. Two of our customers are health systems and both run on this basis.
Do you follow a secure development standard?
Yes. OWASP and SANS guidance is built into the development process. Dovetail also works with third-party experts for regular penetration testing, and findings are addressed rather than logged.
How do you handle patching?
Servers are rebuilt monthly on the latest security patches. Where a component is serverless there is no host to patch. Regular system scans and restricted access policies sit alongside that.
What happens if we are hit by ransomware?
Your HR case data is in AWS rather than on your network, so an event on your estate does not encrypt it. Off-site backups, real-time threat detection and documented disaster recovery sit behind that, and recovery is simulated regularly rather than assumed.
How do you monitor for attacks?
AWS Security Hub, GuardDuty and CloudTrail monitor for anomalous activity across more than a million security events a year. Security logs are retained and readable only by named personnel, with alerting to them for response.
Are you SOC 2 certified?
Yes. Dovetail has achieved Type II AICPA SOC 2 certification for the Dovetail HR SaaS product. The report is available under NDA.
Can we choose where our data is hosted?
Yes. You specify whether your data resides in our US or European data centers, and it stays in that region even where a back-up hosting facility is required.
How is data encrypted?
AES-256 at rest with keys managed in AWS Key Management Service. TLS 1.2 or 1.3 in transit for HTTP, SSH for SFTP, and optional PGP for SFTP file transfers.
Do you support MFA?
Yes. SAML v2 single sign-on with multi-factor authentication, which keeps authentication, geo-fencing and MFA policy under your control.
What is your uptime?
99.9% for secure HR operations, on AWS infrastructure across physically separate availability zones with real-time replication to geographically separate regions.
Do you carry out penetration testing?
Yes. Dovetail collaborates with third-party experts for regular penetration testing, in addition to the compliance programs of our data center provider.
Can we set our own retention schedules?
Yes. Customers can establish retention schedules for their data rather than accepting a vendor default.
Can we stop a record being deleted while litigation is live?
Yes. Cases and employee records carry a purge status that can be set to forbidden or restricted, which exempts them from a retention purge, with notes recording the reason for the restriction.
What international transfer mechanisms do you rely on?
Certification under the EU-U.S. Data Privacy Framework including the UK Extension, and the Swiss-U.S. Data Privacy Framework.
Send us the questionnaire
The SOC 2 Type II report, the Data Privacy Framework notice, the cybersecurity whitepaper and the current penetration test summary all sit in our Trust Center. Request access there and you have them the same day, rather than three weeks into your cycle.