Controls first. Then money moves.
Payroll is the most sensitive system a company runs. Janus is built so that no single person, no stale session, and no silent failure can move money or hide what happened.
No single point of trust.
Maker-checker by design
Preparing a run and releasing money are separated by role. High-stakes transitions require an approver, and overrides require a documented co-signer, one person alone cannot move funds.
Re-authentication for high stakes
Approving a run, starting disbursement, and other high-stakes actions require the operator to re-confirm their password in the moment, inside a short-lived authorisation window - a stolen session is not enough.
Role-gated actions
Every run action is gated server-side by role. The interface only offers what the backend permits. There is no client-side permission logic to bypass.
Sessions, audit, and data.
Bounded by default
Sessions are capped at 12 hours with a 30-minute inactivity timeout. Concurrent sessions are listed in settings and can be revoked individually.
Immutable record
Every sensitive action appends to an append-only audit trail with actor, role, and timestamp. Audit events are never edited or deleted.
Compartmentalised by role
Salary data is visible only to the roles that need it. PII and bank details are encrypted at rest, all traffic is encrypted in transit with TLS, and tenants are strictly isolated on managed AWS infrastructure.
Found a vulnerability? Write to info@januspayroll.com. Security reports are read first.
What your security review will ask.
Certifications: none claimed. Third-party attestations will be published on the Trust Center when obtained, not before.
Run payroll like it matters.
Because it does. Set up your company on infrastructure built for control.