InfraNet HR
Platform
Platform OverviewSee How an Event MovesCommand CenterCaptain & Captain’s LogConciergeImplementation & Case Migration
Solutions
Workers' CompensationOSHA RecordkeepingFMLA AdministrationADA & AccommodationHR InvestigationsEmployee RelationsUnemployment ClaimsPrevent Retaliation RiskOperational Continuity
Why InfraNet
Works With Your HRISThe Latch StoryOperational ContinuityTrust & SecurityCompare InfraNetHR Deserves a Vacation
Resources
BlogLearning HubDocumentationTrust CenterFAQWorkload CalculatorWorkplace Compliance Glossary
Company
About InfraNetOur PhilosophyPress & MediaContact
Client LoginSchedule an Assessment

Security & Operations

InfraNet HR Security Overview

Effective Date: May 30, 2026

Workforce and compliance data is important. InfraNet is designed with security, privacy, and accountability in mind. We understand that organizations trust us with sensitive operational information — workers’ compensation claims, investigation files, FMLA records, safety incident reports, and employee data — and we take that responsibility seriously.

Security Principles

InfraNet’s security program is built on three foundational principles. Least Privilege Access — users should only have access to the information necessary to perform their responsibilities. InfraNet supports role-based access controls (RBAC) with granular, configurable, and auditable permissions. Defense in Depth — security is not a single feature or layer. InfraNet incorporates authentication controls, access restrictions, infrastructure security, network safeguards, application-level protections, and monitoring practices layered together. Continuous Improvement — security is an ongoing process. InfraNet regularly reviews its systems, processes, and controls through internal assessments, dependency reviews, and staying current with emerging threats.

Authentication and Access Control

InfraNet uses secure password requirements and industry-standard hashing; passwords are never stored in plain text. Authentication controls are designed to reduce account-compromise risk, and additional controls are described as available only after production verification. Session controls include timeout periods, token expiration, and session revocation capabilities. Role-based permissions limit access to the data and functions necessary for each user’s work. The platform supports account deactivation, session revocation, and access restriction for former personnel.

Data Protection

All data transmitted between users and InfraNet is encrypted using TLS, protecting data as it moves across networks. Customer data stored within our infrastructure is protected using encryption at rest provided by our hosting and infrastructure providers. InfraNet leverages trusted cloud infrastructure providers that maintain SOC 2-compliant data centers with 24/7 physical security, biometric access controls, climate monitoring, redundant power and network connectivity, and regular third-party audits. InfraNet’s multi-tenant architecture ensures customer data is logically isolated — one organization’s data is never visible to another.

Application Security

Our development team follows secure coding guidelines designed to prevent injection attacks, cross-site scripting (XSS), cross-site request forgery (CSRF), and insecure direct object references. Access controls are validated at the application layer — not just the interface layer — so server-side authorization checks prevent unauthorized data access even if interface manipulation is attempted. Authentication mechanisms include protections against brute force attacks, credential stuffing, and session hijacking. Third-party dependencies are reviewed, kept current, and monitored for known vulnerabilities. Production changes follow defined procedures including testing, review, approval workflows, and change logging.

Monitoring and Logging

The platform generates audit logs recording significant events including authentication attempts, data access, configuration changes, and administrative actions. Monitoring systems detect patterns that may indicate unauthorized access attempts, unusual activity, or potential security incidents. Infrastructure and application health are monitored continuously with alerts for conditions that could indicate security incidents or availability issues. Logging information is retained in accordance with operational and legal requirements.

Incident Response

Security incidents may be detected through monitoring systems, user reports, automated alerts, or third-party notifications. When identified, the immediate priority is containment — isolating affected systems, revoking compromised credentials, or implementing temporary access restrictions. Remediation eliminates the root cause and restores normal operations. A thorough investigation documents root cause, scope of impact, and whether customer data or availability was affected. Affected customers are notified when appropriate and required by applicable law. Lessons learned drive corrective actions to reduce recurrence risk.

Shared Responsibility

Security is a shared responsibility. InfraNet is responsible for platform and infrastructure security, encryption, access controls, monitoring, incident response, business continuity, and transparent policies. Customers are responsible for using strong, unique passwords, managing user access and removing access promptly, reviewing permissions regularly, protecting endpoint devices, following internal retention requirements, and notifying InfraNet of suspected security incidents.

Reporting Security Concerns

If you believe you have identified a security vulnerability, please contact us immediately.
Email: security@infranet-hr.com
Please include a description of the issue, steps to reproduce, and relevant screenshots or supporting information.

Last Updated: May 30, 2026

Company

About InfraNetWhy InfraNet ExistsContactPress & MediaSchedule an Assessment

Platform

Platform OverviewCase ManagementCompliance TrackingIncident ManagementLeave & AccommodationReporting & VisibilityMulti-Organization Management

Solutions

ADA AccommodationsFMLA AdministrationOSHA DocumentationWorkplace InvestigationsWorkers' CompensationEmployee RelationsPrevent Retaliation RiskUnemployment ClaimsOperational Continuity

Trust & Compliance

Trust CenterSecurity OverviewPrivacy PolicyTerms of ServiceAccessibility Statement

Resources

BlogState Compliance Learning HubDocumentationFAQWorkplace Compliance Glossary

© 2026 InfraNet HR. Built by HR, for HR.