Skip to content

Security and privacy

Know what is stored.
Know where the controls end.

Attendance can affect pay and involves sensitive workforce data. This overview describes implemented controls and the decisions that still need to be made for a rollout.

Separate company access from privileged service access

Company administrators authenticate through Supabase Auth. Database row-level policies and capabilities control supported dashboard data access. Worker devices use opaque tokens stored hashed and communicate through server functions, rather than receiving a worker database session.

Privileged worker and ERP functions use service access and enforce their own tenant checks. It would be inaccurate to say row-level security applies to every query regardless of execution context. Within a company, site and organizational scope limitations also matter; review roles and permissions before relying on strict site separation.

What attendance evidence is stored

Accepted attendance includes the capture timestamp, receipt time, site, coordinates, reported accuracy, liveness result and a selfie in private object storage. Event location is captured for attendance; the product does not continuously log a worker’s route between punches.

Optional face matching uses a mathematical reference generated on the device. The enrollment photograph is not uploaded, but the reference is stored server-side and a personal device can keep a secure copy for pre-checking. Accepted attendance selfies are still stored. A template-based system is not a system with no photographs or no sensitive biometric data.

Optional matching and kiosk identification

Personal-device verification compares a claimed worker identity with an enrolled reference. Shared-kiosk identification searches eligible enrolled workers at the kiosk’s site. They have separate rollout gates. Kiosk identification requires internet and is not generally enabled for new companies.

Enrollment records an affirmative notice interaction and version. The appropriate lawful basis, workforce information, fallback and any impact assessment depend on the proposed use and applicable law. Controlled pilot enablement is not a declaration that those decisions are complete for wider rollout.

The client trust boundary

Face inference runs in the app; the server compares the submitted candidate with its reference and applies its decision thresholds. A modified client could submit a fabricated vector. Server-side comparison does not provide device attestation or prove the candidate came from a fresh trusted camera capture.

GPS distance checking likewise evaluates submitted coordinates; it does not authenticate the physical device position. Blink liveness is a capture control, not certified presentation-attack resistance. No fraud-proof or accuracy guarantee is made.

Deletion, retention and operating region

An administrator can reset an active face profile, deleting its template and requiring fresh enrollment. Rejected matching attempts retain outcome metadata rather than the rejected selfie on the server. Personal-device terminal sync rejections remove the local queued capture and selfie.

Attendance records, accepted selfies, templates, logs and backups need distinct retention decisions. A universal customer-configurable retention schedule or selectable data residency is not currently promised. The project’s configured Supabase region is ap-south-1 (Mumbai); confirm hosting and transfer arrangements during procurement.

Review the evidence before rollout

Supported correction and activity records help explain administrative decisions. They are not cryptographic tamper-proof storage or a guarantee of independent approval. SSO/SAML/SCIM, a contractual uptime SLA, named customer-success staffing and a completed certification are not established public offers.

For UK-specific biometric monitoring considerations, see the ICO guidance, which is under review following statutory changes. The privacy policy and data processing document describe the current documented position; deployment-specific contractual and privacy details still need confirmation.

Continue the workflow

Review your data and access requirements.

Tell us your worker and site counts, operating countries and payroll system. We can discuss fit, current availability and the checks needed for your rollout.

Discuss your rollout