Security

Built for HR data from the start

New-hire information is some of the most sensitive data a company handles. Welcomeloom is designed with that in mind.

How We Handle Your Data

Security by design, not by checklist

Encryption in transit and at rest

All data is encrypted with TLS 1.2+ in transit. Stored employee data is encrypted at rest using AES-256.

Role-based access control

HR admins control who can view, edit, and export employee records. Audit logs track every access event.

Built with SOC 2 controls

Welcomeloom is built with SOC 2 Type II controls covering availability, confidentiality, and processing integrity.

Full audit trail

Every workflow action, document submission, and status change is timestamped and logged. Exportable for compliance reviews.

Single-tenant data isolation

Each organization's data is isolated at the database level. There is no shared data layer between tenants.

Data retention and deletion

You control retention periods. Data can be deleted on request. We do not retain employee data after account termination beyond legal requirements.

Compliance Note

On I-9 compliance specifically

Welcomeloom automates the mechanics of I-9 collection and deadline tracking. It does not make eligibility determinations. You remain responsible for Section 2 verification and employer attestation. We provide the workflow; your HR team or a designated manager completes the legal sign-off.

Questions about how we handle your data?

Our team is happy to walk through our security architecture before you sign up.