What we can prove, in one place.
Everything on this page describes controls that exist in shipped code or commitments recorded in our legal terms. We publish mechanisms, not badges, and we claim no certification we do not hold.
Authorisation, access and the audit ledger
Maker-checker, server-side role gates, password re-entry for money movement and the append-only audit ledger are described on the Security page, once, with the facts a security review asks for. This page carries what is specific to trust: who we are, how data is handled, and who touches it.
Who you are dealing with.
How data is protected.
Encryption, sessions, two-factor sign-in, approvals, backups, retention and incident response are stated once, from the infrastructure as configured, on the Security page. Nothing there is repeated here so the two pages cannot drift apart.
Who touches the data.
Certifications: none claimed. When we obtain third-party attestations, they will be published here, not before. Vulnerability reports: info@januspayroll.com, read first.
See also: Security · Privacy Policy · Terms of Service
Diligence us properly.
Ask the hard questions. We answer with mechanisms. Or see the controls from the inside.