Security & compliance

What we actually do to protect your company and employee data — not a checklist of buzzwords.

No passwords, anywhere

Every portal — HR, Seller, Admin — authenticates by phone number and a one-time code, never a stored password. There's nothing resembling a password database to leak.

Signed, expiring sessions

Login sessions are cryptographically signed and expire automatically. A copied session cookie can't be silently extended or reused past its expiry.

Tenant-isolated data

Every record — employees, gift rules, wallet, orders — is scoped to a single company. One company's HR account has no path to another company's data, by construction, not just by application-level filtering convention.

Role-scoped access within your team

HR accounts distinguish an Owner (wallet, billing, inviting other HR users) from Members (day-to-day employee, gift-rule, and campaign management) — so not everyone on your People team needs financial access to do their job.

GST-compliant invoicing

Every wallet top-up generates a proper GST invoice automatically, so your finance team has an audit trail without manual reconciliation.

Minimal data over WhatsApp

Employee-facing WhatsApp messages carry a personal claim link, nothing else. Delivery addresses are only collected at the point a physical gift is actually claimed, and only reused for that employee's future physical claims.

Where we are today

TreatVibes is an early-stage platform. We follow the practices above by design, but we have not yet pursued formal third-party certifications (SOC 2, ISO 27001, or similar) — we'd rather say that plainly than imply a certification we don't hold. If a compliance audit is a hard requirement for your organization, tell us on the Contact page and we'll give you a straight answer on where things stand.