Security & compliance
What we actually do to protect your company and employee data — not a checklist of buzzwords.
No passwords, anywhere
Every portal — HR, Seller, Admin — authenticates by phone number and a one-time code, never a stored password. There's nothing resembling a password database to leak.
Signed, expiring sessions
Login sessions are cryptographically signed and expire automatically. A copied session cookie can't be silently extended or reused past its expiry.
Tenant-isolated data
Every record — employees, gift rules, wallet, orders — is scoped to a single company. One company's HR account has no path to another company's data, by construction, not just by application-level filtering convention.
Role-scoped access within your team
HR accounts distinguish an Owner (wallet, billing, inviting other HR users) from Members (day-to-day employee, gift-rule, and campaign management) — so not everyone on your People team needs financial access to do their job.
GST-compliant invoicing
Every wallet top-up generates a proper GST invoice automatically, so your finance team has an audit trail without manual reconciliation.
Minimal data over WhatsApp
Employee-facing WhatsApp messages carry a personal claim link, nothing else. Delivery addresses are only collected at the point a physical gift is actually claimed, and only reused for that employee's future physical claims.
Where we are today
TreatVibes is an early-stage platform. We follow the practices above by design, but we have not yet pursued formal third-party certifications (SOC 2, ISO 27001, or similar) — we'd rather say that plainly than imply a certification we don't hold. If a compliance audit is a hard requirement for your organization, tell us on the Contact page and we'll give you a straight answer on where things stand.