Security

Controls first. Then money moves.

Payroll is the most sensitive system a company runs. Janus is built so that no single person, no stale session, and no silent failure can move money or hide what happened.

Authorisation

No single point of trust.

Approvals

Maker-checker by design

Preparing a run and releasing money are separated by role. High-stakes transitions require an approver, and overrides require a documented co-signer, one person alone cannot move funds.

Step-up auth

Re-authentication for high stakes

Approving a run, starting disbursement, and other high-stakes actions require the operator to re-confirm their password in the moment, inside a short-lived authorisation window - a stolen session is not enough.

Access control

Role-gated actions

Every run action is gated server-side by role. The interface only offers what the backend permits. There is no client-side permission logic to bypass.

Platform

Sessions, audit, and data.

Sessions

Bounded by default

Sessions are capped at 12 hours with a 30-minute inactivity timeout. Concurrent sessions are listed in settings and can be revoked individually.

Audit

Immutable record

Every sensitive action appends to an append-only audit trail with actor, role, and timestamp. Audit events are never edited or deleted.

Data protection

Compartmentalised by role

Salary data is visible only to the roles that need it. PII and bank details are encrypted at rest, all traffic is encrypted in transit with TLS, and tenants are strictly isolated on managed AWS infrastructure.

Found a vulnerability? Write to info@januspayroll.com. Security reports are read first.

Facts

What your security review will ask.

Encryption in transit
All traffic between browsers, the API and the payment providers is encrypted with TLS.
Encryption at rest
Database storage is encrypted at rest with AWS-managed keys, and every file store (payslips, exports, uploads, invoices) uses server-side encryption. National identifiers (NIN, BVN) are additionally encrypted at the application layer and are never returned in full.
Tenant isolation
Every query is scoped to the employer account; cross-tenant access is refused at the API layer, and a pasted URL from another company returns not found.
Two-factor sign-in
Any user can add an authenticator app (Microsoft Authenticator, Google Authenticator, Authy, any TOTP app) to their sign-in, with one-time backup codes. Five wrong codes lock the attempt; changing or removing the app requires the account password and is written to the activity log.
Hosting
Amazon Web Services. Customer data does not leave the AWS environment; the specific region and a completed security questionnaire are available to customers on request.
Backups
Automated daily database backups with point-in-time recovery, retained for 7 days and encrypted with the same keys as the database.
Retention
Payroll and audit records are retained to meet Nigerian statutory record-keeping requirements, then deleted or anonymised, as set out in the Privacy Policy.
Incident response
A confirmed security incident involving your data is notified to your account Owner by email within 72 hours of confirmation: what happened, what was affected, what we did. The Nigeria Data Protection Commission is notified where the NDPA requires it.
Access to your data
Janus staff reach customer data only through the support console, where every action is recorded with the staff member, the reason and the time.

Certifications: none claimed. Third-party attestations will be published on the Trust Center when obtained, not before.

Run payroll like it matters.

Because it does. Set up your company on infrastructure built for control.

Or write to us: info@januspayroll.com