Skip to main content
Hirebase
Home/Platform/Customer-Controlled Azure
Cloud Security & Architecture

Customer-Controlled Azure & Biometric Security.

Deploy Hirebase inside your organization's own Microsoft Azure tenancy. Retain complete data sovereignty, dedicated single-tenant database perimeters, and Works Council biometric compliance—with zero employee records co-mingling in shared vendor clouds.

Verified Claim:Hirebase Security & Architecture Specification (BYOC Tenant Model)(§2.1–§3.4 Single-Tenant Isolation & Encryption)Verified: September 2026Methodology
Download Security Whitepaper (PDF)
Tenancy

Single-Tenant

Dedicated isolated compute and database within your Azure subscription boundary.

Key Custody

Customer-Owned

Customer manages encryption keys via Azure Key Vault; data is encrypted at rest and in transit.

Biometrics

On-Device AI

Face anti-spoofing vectors processed on phone; raw employee photos never hit shared clouds.

Compliance

Works Council

Strict GPS boundary check at punch time only; zero continuous background employee tracking.

Tenant Isolation Model

Your Azure cloud perimeter. Zero shared infrastructure.

Most workforce SaaS platforms pool hundreds of enterprise customers into one enormous multi-tenant cluster. If another tenant experiences a breach or an API outage, your workforce operations and sensitive biometric telemetry are exposed.

Dedicated Azure Resource Group

Application containers, Azure SQL, and blob storage provisioned inside your corporate subscription, isolated from all other Hirebase clients.

Identity & Access Governance

Role-based access controls integrate directly with Microsoft Entra ID (Azure AD) and SAML/SSO. Your IT team provisions and revokes access.

Sovereign Audit Logging

Every shift change, manager punch override, and geofence adjustment streams directly into your Azure Monitor and SIEM pipelines.

Corporate compliance auditor reviewing workforce compliance records and checklists in office

Enterprise Compliance & Sovereign Data Perimeter

Customer data sovereignty maintained within dedicated Azure boundaries.

Frontline hourly worker performing live mobile facial verification on site

Live Mobile Verification at the Work Site

Facial anti-spoofing vectors computed locally on the worker's mobile device.

Biometrics & Privacy

Works Council compliant anti-spoofing biometrics

Enterprise employers must eliminate buddy punching and ghost workers without infringing upon worker privacy rights or violating strict labor union regulations.

On-Device Liveness Extraction

Hirebase verifies facial liveness directly on the employee's phone. Anti-spoofing algorithms detect printed photos, phone-screen replays, and masks in real-time.

No Continuous Location Tracking

GPS coordinates are only evaluated during punch-in and punch-out events to verify site radius. The mobile application never monitors employee movement during shifts or off-duty hours.

Zero Third-Party Model Training

Worker facial templates and telemetry are never used to train public machine learning models or shared with external third-party brokers.

Operational Fit & Deployment Suitability

Hirebase is designed for organizations requiring enterprise-grade security and single-tenant cloud boundaries.

Ideal Operational Fit

  • Enterprises requiring single-tenant data isolation inside their own Microsoft Azure cloud tenancy
  • Operations subject to strict Works Council, HIPAA, SOC 2, or regional data residency compliance
  • Security-conscious IT leadership that prohibits employee biometric data from co-mingling in shared multi-tenant clouds
  • Organizations requiring custom single sign-on (SSO) and role-based access through Microsoft Entra ID
  • Multi-site frontline operations managing over 200 hourly staff across distributed field or facility locations

Not Designed For

  • Companies seeking instant self-serve consumer SaaS without enterprise IT oversight or cloud configuration
  • Teams with fewer than 20 hourly employees that do not require isolated database perimeters or enterprise compliance
  • Organizations looking for simple honor-system web punch tools without verified mobile location telemetry
Implementation & Configuration Boundaries
  • Geofence perimeters are admin-selected per job location and can be configured down to 10 metres (250m is a configuration option, not a universal platform default).
  • Safety questionnaire sequences, training activation gates, and manager review tiers are tailored per client implementation rather than enforced as a rigid software template.
  • Current live customer deployments are located in North America; Azure architecture provides global technical deployability.
  • Native payroll connectors are ready for ADP, QuickBooks, Paychex, and CFS. Enterprise ERP connections (SAP, Oracle, Workday, Dynamics) are engineered per client implementation.

Security Matrix

Hirebase Azure Single-Tenant vs. Industry Alternatives

A factual technical breakdown of security controls, tenancy boundaries, and data custody across workforce platforms.

Security ControlHirebase (BYOC Azure)Standard SaaS (e.g. Deputy)Legacy ERP (e.g. UKG)
Database IsolationDedicated Private Azure SQL (No Co-Mingling)Shared Multi-Tenant Public DatabaseVendor Cloud Multi-Tenant Hosted
Encryption Key CustodyCustomer-Owned (Azure Key Vault)Vendor-Managed Shared KeysVendor-Managed Shared Keys
Biometric Data ResidencyIsolated Within Customer PerimeterExternal Shared Vendor ServerFixed Proprietary Hardware Kiosks
Works Council TelemetryPunch-Time Only (Zero Background Tracking)Continuous Background App PingsStationary Badge Readers
Audit & SIEM IntegrationDirect Native Stream to Azure MonitorRate-Limited REST API PollingComplex Custom Batch Logs

Architecture Questions

Frequently asked security & deployment questions

Technical inquiries from enterprise CISOs, CTOs, and compliance committees.

What does 'Customer-Controlled Azure' (BYOC) mean in practice?

Unlike multi-tenant workforce software where all customer data co-mingles in a shared database, Hirebase deploys dedicated application and database instances inside your organization's Microsoft Azure cloud boundary. Your IT department owns the subscription, controls encryption keys, manages access control via Microsoft Entra ID (Azure AD), and governs network access.

Where are facial biometric templates stored and who has access to them?

Biometric facial verification occurs directly on the employee's mobile device during clock-in. Mathematical vectors are calculated locally with active anti-spoofing liveness detection. Biometric templates are stored solely in your dedicated Azure instance and are never exported, shared, or processed through third-party multi-tenant AI services.

How does this architecture satisfy European Works Council and strict privacy regulations?

By isolating all workforce telemetry within the employer's private cloud perimeter, Hirebase satisfies strict data residency and privacy statutes including GDPR and Works Council guidelines. GPS coordinates are only captured at the exact moment of clock-in and clock-out to verify location radius, with zero continuous background tracking.

Which geographic Azure regions can Hirebase be deployed into?

While current live customer deployments are situated across North America, the containerized Azure architecture can be provisioned into any commercial Microsoft Azure region worldwide, including US East/West, Canada Central, UK South, Europe West, and UAE North.

How do updates and security patches get applied to our private instance?

Hirebase delivers automated, non-disruptive container updates and vulnerability patches via secure Azure DevOps pipelines approved by your enterprise change management policy. Your IT security team retains full audit logs of all code changes and deployments.

One record. Application to exit.
Nothing rekeyed.

We will map Hirebase to your compliance framework,
your ERP and your region.