Your employee and payroll data is critically sensitive. Here's exactly how PayMATE protects it at every layer — from transit to storage to access control.
PayMATE handles some of the most sensitive data in your organization — employee personal information, salary records, government ID numbers, and biometric logs. We treat the security of this data as a fundamental responsibility, not an afterthought.
Our security practices are designed to comply with the Republic Act No. 10173 (Data Privacy Act of 2012) and the guidelines of the National Privacy Commission (NPC) of the Philippines.
✅ PayMATE is operated by Tigernethost OPC, a Philippine-based IT services company with experience in cybersecurity consulting and secure cloud infrastructure.
All communication between your browser or mobile device and our servers is encrypted using TLS 1.2 and TLS 1.3 protocols. We enforce HTTPS across all pages and API endpoints. HTTP connections are automatically redirected to HTTPS.
Sensitive data fields — including government ID numbers, bank account details, and salary information — are encrypted at rest using AES-256 encryption before being stored in our database.
User passwords are never stored in plain text. We use bcrypt hashing with salting to protect all authentication credentials.
PayMATE uses a Role-Based Access Control (RBAC) system to ensure users can only access data appropriate to their role:
Access logs are maintained for all sensitive operations. All login attempts, payroll runs, and data exports are recorded with timestamps and user identifiers.
PayMATE is hosted on secure cloud infrastructure with the following protections:
Our development team follows secure coding practices to protect against common web vulnerabilities:
We maintain a comprehensive backup strategy to ensure data availability and business continuity:
✅ Our target Recovery Point Objective (RPO) is 24 hours and Recovery Time Objective (RTO) is 4 hours for critical system failures.
PayMATE integrates with ZKTECO biometric attendance devices. We treat biometric data with the highest level of sensitivity:
PayMATE never receives, stores, or processes raw biometric identifiers such as fingerprint templates or facial recognition data.
Employee records in PayMATE — including government ID numbers, salary information, and bank account details — are protected by:
In the event of a confirmed security incident or data breach, we follow a structured response process:
Under the Data Privacy Act of 2012, we are legally required to report personal data breaches that may pose a real risk to data subjects to the NPC within 72 hours.
Security is a shared responsibility between PayMATE and our clients. Here's how responsibilities are divided:
| Responsibility | Who |
|---|---|
| Platform infrastructure & server security | PayMATE |
| Application code security & updates | PayMATE |
| Data encryption in transit & at rest | PayMATE |
| Backup & disaster recovery | PayMATE |
| Account password security | Client |
| Managing user roles & permissions | Client |
| Accuracy of employee data entered | Client |
| ZKTECO device physical security | Client |
| Reporting suspicious activity promptly | Client |
If you discover a potential security vulnerability or data breach, please use the secure form below to report it responsibly. We commit to acknowledging valid reports within 48 hours in accordance with the Data Privacy Act of 2012.
PayMATE DPO — Tigernethost OPC
📧 [email protected] ·
📍 Pampanga, Philippines