Signed URLs for every capture
Screenshots, screen recordings and any binary artifact are served only through short-lived signed URLs (exp / nonce / sig). Direct object access requires a valid signature — no raw filesystem exposure.
Status Quo 247 is built consent-first and audit-everything. Role-scoped by default, transparent to the people being measured, and honest about what's shipped versus what's on the roadmap.
Screenshots, screen recordings and any binary artifact are served only through short-lived signed URLs (exp / nonce / sig). Direct object access requires a valid signature — no raw filesystem exposure.
Eight system roles (Super Admin, Admin, Manager, HR, Employee, HR Payroll, Finance Payroll, Payroll Checker) plus custom roles built from a granular resource:action permission catalog. SAML SSO and SCIM 2.0 user provisioning on Enterprise.
Every sensitive admin action — user changes, permission grants, policy edits — is captured in an append-only audit log. Filter, search, and export to CSV from the platform panel.
Multi-tenant by design. Every table is orgId-scoped and every request is pinned to the caller's org by a global interceptor — one org's data is never queryable from another's session.
Per-org retention windows for captures (90 days default), audit logs (365), system-info snapshots (30) and geo-IP records (90). A nightly prune scheduler enforces the policy — expired rows are permanently deleted, not soft-hidden.
First-launch consent lists the current policy version and exactly what's captured. Consent state (accepted / withdrawn) is stored per-employee. Stealth vs Visible mode is a single explicit org-level policy — no hidden default.
Monitoring only earns trust when it's transparent. Status Quo 247 is built so employees know what's measured, managers see only what their role allows, and every sensitive action leaves a trace.
We won't claim a certification we haven't earned. Here's the honest picture — send us your security questionnaire and we'll answer it point by point.
DPA, architecture overview and a walkthrough with an engineer — on request.
What enterprise buyers ask us most.
Yes. We operate under GDPR as data processor for your organization's employee data. We sign a Data Processing Agreement (DPA), maintain a Record of Processing Activities, honor Data Subject Access Requests, and support the right to erasure. See our /legal/dpa page for the standard DPA text; enterprise customers can negotiate custom terms with legal@statusquo247.com.
By default, in AWS ap-south-1 (Mumbai). We can provision your tenant in EU (eu-west-1, Frankfurt) or US (us-east-1) regions on Enterprise plans. Data never leaves the region you provision in.
In transit: TLS 1.3 with modern ciphers only, HSTS on every subdomain. At rest: AES-256 on Postgres storage, application-level field encryption on sensitive payroll data (bank details, tax IDs) using per-org keys.
Only a small number of platform operators, with just-in-time access that expires in 30 minutes and is logged in an immutable audit trail. Every operator action against a tenant is recorded and available to you on request. No engineer has standing access to production customer data.
SOC 2 Type II is in-progress; report expected Q3 2026. ISO 27001 is on the roadmap for 2027. For deals that need proof-of-controls today, we can provide our security questionnaire responses, penetration test results, and a signed DPA. Reach security@statusquo247.com.
You can export everything via the admin panel or API before cancellation. After cancellation we retain per your plan's retention window (30 days on Growth, up to 12 months on Enterprise), then permanently delete. Backups are purged within 35 days of primary deletion.
We follow a standard incident response process: detection → containment → notification to affected customers within 72 hours (as GDPR requires) → post-mortem shared with impacted customers. Our status page publishes incidents in real time.