Built for shift teams:
Designed for EU Working Time rules
|

Security: Encryption, Access Control & GDPR

How Chegatta keeps your attendance data secure: encryption in transit and at rest, role-based access control, and continuous monitoring.

We take data security seriously

Your attendance records are sensitive. Here is how we protect them, every day.

Encryption in transit

All traffic to and from Chegatta is encrypted with TLS 1.2 or higher, protecting data as it travels.

Encryption at rest

Databases and backups are encrypted at rest, so stored data is unreadable without authorized keys.

Access control

Role-based permissions ensure admins, managers, and employees only see the data they need.

Hosting and infrastructure

Chegatta runs on Amazon Web Services (AWS) using best-in-class infrastructure. Our hosting environment includes network isolation, managed firewalls, and automated backups with defined retention. Physical access to servers is restricted and monitored by AWS.

Enterprise-grade foundations

Three layers of protection on every record: TLS 1.2+ in transit, encryption at rest, and role-based access control — with continuous monitoring on top.

Application security

  • All data in transit is encrypted with TLS 1.2 or higher using modern cipher suites.
  • Passwords are stored only as salted, iterated hashes. They are never stored in plaintext.
  • We follow secure coding practices including input validation, parameterized queries, and protection against injection and cross-site scripting (XSS).
  • Your data is logically isolated per account, and access is enforced through role-based authorization.

Monitoring and incident response

We monitor systems continuously for unusual activity and unauthorized access attempts. We maintain an incident response plan and will notify affected customers promptly if a security incident is confirmed.

Data retention and deletion

When you delete data or cancel your account, records are removed from active storage and from backups according to our Privacy Policy . Export tools are available so you always retain control of your data.

Reporting a vulnerability

Found a security issue? We appreciate responsible disclosure. Email security@chegatta.com with details and we will respond promptly. Please do not disclose the issue publicly before we have had a chance to address it.

Want to evaluate security for your business?

Start a free trial or send us your security questionnaire and we will get back to you quickly.

Instant 2-Minute Setup • No Credit Card Required

Start Running Accurate Shift Roster & GPS Clock-In Today

Zero hardware cost. Automate time tracking, shift verification and banking-grade SEPA payroll exports.

14 days full accessZero setup hardwareCancel anytime

Frequently Asked Questions

Chegatta complies strictly with GDPR Article 88. Coordinates are requested solely at the sub-second moment a worker presses "Clock In" or "Clock Out" to verify presence inside the employer’s designated worksite polygon. There is zero background tracking, no continuous location pinging, and GPS telemetry is completely disabled during active working shifts.