A clearer view of the work behind every people decision See what to verify ↗
EVALUATION / SECURITY & ACCESS

Understand access before you adopt.

HR software handles sensitive information. HR Nova's frontend uses sign-in, bearer-token requests, route guards and role/permission checks. Company records are isolated, and HR Nova uses firewalls, data encryption and AWS WAF. Discuss the controls and documentation relevant to your deployment during evaluation.

ACCESS REVIEW / EVALUATION•••
01
VISIBLE IN THE FRONTENDSign-in · Token · Route guard · Role checks
UI
↓   Requires independent verification   ↓
02
SERVER EVIDENCE TO REQUESTAuthorization · Company boundaries · Exports
?
A screen cannot establish server-side protection.
Ask for evidence,
endpoint by endpoint.
ACCESS IS A QUESTION TO TESTEXPLORE THE REVIEW ↓
WHAT THE APPLICATION SHOWS

Visible controls.
Clear boundaries.

Sign-in leads to an authenticated application shell. The route guard checks for a token and expiry, some routes declare role requirements, and requests send a bearer token to the API.

01 / SIGN-IN

Authenticated shell

Sign-in leads into an application layout with a token-aware route guard.

02 / ROLE CHECKS

Role-aware routes

Some routes declare role requirements, and screens include permission checks.

03 / ADMINISTRATION

Admin screens

Administrator views include roles and tenant records for evaluation.

WHAT YOUR SECURITY TEAM SHOULD TEST

Proof lives
beyond the UI.

Bring your role matrix and sensitive-data scenarios. Ask the responsible owners for documented retention, logging, backup, incident and deployment controls.

Review access together ↗
SERVER-SIDE QUESTIONS / SYNTHETIC TESTS01 → 04
01Does the server deny another role’s action?
02Can a user retrieve another employee’s payslip?
03Do company boundaries hold on sensitive endpoints?
04Do exported files follow the same permissions?
Request independent server and process evidence for each answer.
REVIEW AGAINST YOUR REQUIREMENTS

Bring the roles.
Bring the scenarios.

Use invented employee and company records to test access. A synthetic role-specific screen can illustrate the UI, but it cannot prove server controls.

USEFUL INPUT FOR THE EVALUATION
01Role and permission matrix
02Sensitive employee-data scenarios
03Company-boundary questions
04Export and download requirements
QUESTIONS BUYERS ASK

Direct answers.
Evidence next.

Use these answers to focus your security review on the evidence still needed.

What security measures are used?

HR Nova uses firewalls, data encryption and AWS WAF.

Is HR Nova certified to a security standard?

No certification evidence was available for this package.

Is data isolated between companies?

Yes. Each company's records are isolated from those of other companies.

Is SSO available?

SSO is not currently available. It is planned for a future release.

REVIEW ACCESS AGAINST YOUR REQUIREMENTS

Bring your matrix.
Test the path.

Bring role and sensitive-data scenarios to an evaluation. Ask for server-side evidence behind every access decision that matters to your team.

Role actionsPayslip accessCompany boundariesExports
Request a demo ↗Tell us which access questions you need answered.