Security & architecture

Your people data deserves
a serious foundation.

HRlume combines modern access controls, managed operational oversight and Cloudflare-native infrastructure with options for fully dedicated deployment.

Application controls

Protection built into everyday workflows.

Security is part of the product, not a separate premium tier.

01

Strong authentication

PBKDF2 password hashing, configurable password policies, TOTP two-factor authentication and controlled session inactivity windows.

02

Identity provider support

Optional Google, Microsoft or LDAP/Active Directory single sign-on for existing, verified employee accounts. Password sign-in remains available as a recovery path.

03

Least-privilege access

Fixed roles and granular custom permissions keep sensitive HR actions restricted to the people who need them.

04

Traceable changes

A company-wide audit log records sensitive administrative, employee-lifecycle and performance actions with actor and time context.

05

Scoped integrations

API keys use explicit resource-level read and controlled write scopes, optional expiry and IP allowlists instead of becoming general-purpose sessions.

06

Private file delivery

Documents are streamed through authenticated application routes instead of being exposed through a public storage bucket.

07

Company-wide 2FA policy

Administrators can let employees enable TOTP individually or require two-factor authentication across the organisation.

08

Session and password policy

Configure password requirements and inactivity limits to match the organisation's access policy.

09

Candidate privacy controls

Configure GDPR consent, retention period, privacy-policy link and DPO contact details for recruiting data.

Operational assurance

A secure control plane behind every managed HRlume environment.

HRlume separates the customer HR workspace from the internal service controls used to operate the platform. The result is clearer oversight without exposing administrative infrastructure to customer users.

  • Licence status and upcoming-expiry monitoring
  • Connected-instance health and platform visibility
  • Controlled update requests and deployment state
  • Protected administrator access with 2FA and audit history

The visual is illustrative and intentionally contains no customer records, domains or internal credentials.

HRlume Control PlaneOperational
OPERATIONS CENTREPlatform overview
All systems operational
Managed environments18
Active licences17
Attention needed1
Environment healthConnected
Update channelControlled
Administrator auditProtected
Cloudflare-native architecture

A small, auditable stack with fewer moving parts.

The application runs as a Cloudflare Worker, stores structured data in D1 and keeps uploaded files in R2. There are no always-on application servers to patch or maintain.

WorkersApplication runtime and authenticated APIs
D1Structured HR and configuration data
R2Private document and file storage
Web CryptoSigning, hashing and verification primitives
Dedicated deployment

Your account. Your database. Your storage.

For organisations that require stronger infrastructure isolation, HRlume can provision a complete application instance inside the customer's own Cloudflare account.

  • A dedicated Worker, D1 database and R2 bucket
  • Customer-owned Cloudflare resources
  • A licence bound to the new application URL
  • The provisioning token is used for that request and not retained by HRlume
Discuss a dedicated instance
1

Your Cloudflare accountScoped provisioning access

2

Dedicated HRlume stackWorker · D1 · R2

3

Your HR workspaceIsolated and licensed

Security questions?

Let's review your requirements together.

Tell us about your identity, access, deployment and data-isolation needs.

Start a conversation