Shiftaro Trust Center

Security at Shiftaro

Shiftaro is designed to protect workforce information through trusted cloud infrastructure, authenticated access, organization-level data separation, scoped permissions, audit records, and secure operating practices.

Last updated: July 28, 2026

Security contact

Report a security concern

Send suspected vulnerabilities, account-security concerns, or responsible disclosure reports to security@shiftaro.com.

Please do not include passwords, authentication tokens, employee records, or other sensitive information in your initial message.

Authenticated accessProtected application features require a valid account session
Organization separationWorkforce records are scoped to the customer organization
Permission controlsAdministrative actions use role and scope-aware authorization
Operational traceabilityImportant actions can generate audit records

Security overview

Shiftaro applies layered safeguards across infrastructure, application access, workforce permissions, operational logging, and internal processes.

Our security program is designed to grow with the platform. We describe only controls and practices we can reasonably support and do not claim certifications or guarantees that have not been independently verified.

1. Security principles

Shiftaro’s security approach is guided by practical principles intended to reduce unnecessary access and protect workforce information throughout its lifecycle.

Least necessary access

Access should be limited to the people and systems that need it for an authorized business purpose.

Customer-controlled administration

Customers control account membership, access levels, location and team assignments, and operational permissions.

Backend enforcement

Protected actions are designed to be validated by the backend rather than relying only on hidden buttons or frontend behavior.

Traceable changes

Important workforce and administrative actions can generate audit records to support review and accountability.

2. Cloud infrastructure and encryption

Shiftaro uses trusted cloud service providers to host and operate the platform. These providers support encryption of data in transit and at rest within their managed environments.

Encryption in transit

Shiftaro uses encrypted HTTPS connections to protect information transmitted between supported browsers, applications, and backend services.

Encryption at rest

Application databases, storage, and managed backups are hosted on cloud infrastructure designed to encrypt stored data at rest. Shiftaro does not publicly disclose unnecessary infrastructure details that could increase operational risk.

Important distinction: Platform-level encryption at rest does not mean every individual data field is separately encrypted inside the application. Shiftaro evaluates additional field-level protections based on data sensitivity and product requirements.

3. Account access and authentication

Protected application features require authentication. Shiftaro uses account and session controls designed to verify user access before returning or changing workforce information.

  • Passwords are handled through managed authentication functions rather than stored or displayed as readable text.
  • Password-reset links are time-limited and designed for one-time use.
  • Inactive accounts can be blocked from application access.
  • Authentication and selected account-security events can be recorded for review.
  • Customers are responsible for promptly deactivating users who should no longer have access.

Shiftaro may introduce additional authentication controls, such as multi-factor authentication or enterprise identity integrations, as the platform develops.

4. Roles, permissions, and data separation

Shiftaro is designed as a multi-tenant workforce platform. Customer records are associated with an organization, and backend queries and actions are designed to restrict access to the authenticated user’s organization.

Access levels

Customer accounts may use access levels such as Owner, Admin, Manager, and Employee. These access levels are separate from an employee’s job title or company position.

Scoped permissions

Administrative and management actions may be limited by organization, location, or team scope. Examples include managing schedules, approving requests, managing users, viewing reports, and changing settings.

Customer configuration

Customers are responsible for assigning appropriate access, reviewing administrator and manager permissions, and removing access when a person changes responsibilities or leaves the organization.

5. Application security

Shiftaro uses backend validation and controlled application workflows to reduce unauthorized actions and inconsistent workforce records.

  • Protected endpoints can require an authenticated user.
  • Records can be checked against the authenticated user’s organization before access or changes are allowed.
  • Selected management actions can require explicit permission checks.
  • Controlled update workflows can prevent direct changes to protected state fields.
  • Scheduling actions can validate location, team, employee, qualification, and policy context before committing changes.
  • Important multi-step changes may use database transactions so related updates succeed or fail together.

Security controls are reviewed and improved as features are added and before broader production use.

6. Logging and auditability

Shiftaro can record important authentication, administrative, scheduling, approval, and workforce-operation events. Depending on the feature, records may include the acting user, action type, affected record, date and time, success status, and technical context used for investigation.

Audit records are intended to support accountability, troubleshooting, security review, and customer operations. They are not a substitute for a customer’s own legal, payroll, labor, or compliance records.

Shiftaro works to avoid intentionally placing passwords or authentication secrets in customer-facing logs or responses.

7. Availability and backups

Shiftaro relies on managed cloud infrastructure that provides database storage, media storage, operational capacity, and backup capabilities.

We use reasonable practices intended to support service continuity and data recovery. However, unless Shiftaro signs a separate written service-level agreement, the platform does not promise a specific uptime percentage, recovery time, recovery point, or uninterrupted availability.

Customers should maintain appropriate copies of information they are legally or operationally required to preserve outside any single software platform.

8. Secure development and change management

Shiftaro’s development process emphasizes backend authorization, input validation, organization scoping, controlled state transitions, audit consistency, and dependency-aware changes.

Security-relevant findings are tracked for remediation and release planning. New features may be tested in development or preview stages before broader release.

Shiftaro does not currently claim that every release receives an independent penetration test, formal secure-code certification, or third-party audit.

9. Incident response

Shiftaro maintains a process for receiving, investigating, containing, and responding to suspected security events.

If we determine that a security incident affects Customer Data, we will evaluate the event, take reasonable steps to reduce harm, preserve relevant information, and provide notices as required by applicable law and our agreements.

Customers should report suspected account compromise promptly and preserve relevant details such as dates, affected users, screenshots, and unexpected activity.

10. Service providers

Shiftaro uses trusted service providers to support functions such as cloud hosting, application delivery, email communications, payment processing, analytics, and customer support.

We evaluate provider access based on the services they perform and seek to limit access to what is reasonably necessary. Providers are expected to handle information according to applicable contracts, security obligations, and law.

Shiftaro does not publish unnecessary infrastructure secrets, access keys, internal endpoints, or detailed security configurations.

11. Customer responsibilities

Security is a shared responsibility. Customers play an important role in protecting their workforce information.

  • Assign the minimum access each user needs.
  • Review Owner, Admin, and Manager access regularly.
  • Deactivate users promptly when access is no longer appropriate.
  • Use strong, unique passwords and protect account recovery channels.
  • Keep devices, browsers, and operating systems updated.
  • Avoid placing unnecessary medical, financial, government-identifier, or other highly sensitive information in general notes or chat fields.
  • Verify payroll exports, schedules, approvals, and compliance decisions before relying on them.
  • Report suspected compromise or unauthorized activity promptly.

12. Current assurance status

Shiftaro is actively building and maturing its security program. Unless expressly stated in a signed agreement, Shiftaro does not currently represent that it is:

  • SOC 2 certified or attested;
  • ISO 27001 certified;
  • HIPAA compliant or approved for protected health information;
  • PCI DSS certified as a merchant data environment;
  • subject to a guaranteed uptime or support SLA; or
  • independently penetration-tested on a stated recurring schedule.

Payment card information is intended to be processed by Shiftaro’s payment provider rather than stored directly by Shiftaro.

Healthcare use: Customers should not submit protected health information unless Shiftaro has expressly authorized that use and the parties have completed any required agreement, including a Business Associate Agreement where applicable.

13. Responsible disclosure

We welcome good-faith reports that help improve Shiftaro’s security.

When reporting a potential vulnerability:

  • Provide enough detail for us to understand and reproduce the issue.
  • Do not access, modify, delete, or download data that does not belong to you.
  • Do not disrupt the service, use denial-of-service testing, send spam, or perform destructive testing.
  • Do not publicly disclose an unresolved issue before giving Shiftaro a reasonable opportunity to investigate.
  • Do not include live passwords, private keys, authentication tokens, or real employee records in the initial report.

Shiftaro does not currently operate a paid bug-bounty program and cannot promise compensation for submitted reports.

14. Contact us

For security questions, suspected vulnerabilities, or account-security concerns, contact:

Shiftaro, LLC
security@shiftaro.com

For privacy requests, contact privacy@shiftaro.com.