Meet Umi Intelligence. Workforce context. Human-led decisions.Explore the assistant →
Security & governance

Clear access.
Accountable actions.

People records need thoughtful controls. UmiHR combines workspace scoping, role permissions, protected sensitive values and reviewable activity.

Product controls

Protection built around the workflow.

Workspace & employee scope

Access is derived from the authenticated user, selected workspace, active membership, permissions and employee relationship. Copying a record identifier does not grant additional authority.

Identity & sessions

The application supports password hashing, optional TOTP multi-factor authentication, server-side sessions and production cookie protections. Account lockout and rate limiting support login controls.

Sensitive information

Bank and tax identifiers have encrypted storage and additional permission checks. SMTP credentials and queued message content also use application-level encryption.

Private document delivery

Uploads use private paths, allowed content types and size limits. Download access is authenticated, with metadata and file digests retained in the document record.

Separated decision authority

Leave, expense and access decisions use specific permissions. Payroll preparation, approval and publication have separate authority, and external payroll partners cannot publish.

Audit & operational history

Important actions create audit events. Email operations retain delivery attempts, while authorised record detail includes relevant status, contextual notes and safe activity history.

Responsible intelligence

Advisory AI, with a human decision boundary.

Umi Intelligence uses aggregate workspace context through its implemented endpoint. Raw employee records are not automatically included in the external AI prompt.

People remain responsible for the prompts they enter, the output they use and the decisions they make. Local advisory mode is available without an external provider.

Explore Umi Intelligence
  • Review output against the relevant operational records.
  • Avoid entering unnecessary personal information in prompts.
  • Use appropriate organisational policies for external providers.
  • Do not delegate consequential employment decisions to AI.

A shared responsibility model.

The application’s controls need appropriate deployment and operating practices. Review administrators, role assignments and account status regularly. Remove access when it is no longer needed, protect authentication details and maintain approved data-handling procedures.

Deployment and recovery

Agree HTTPS configuration, infrastructure maintenance, monitoring, database backups, private-document backups and tested recovery procedures for the chosen deployment. The standard release keeps private uploads on the application filesystem; multi-worker deployments require suitable shared storage arrangements.

Assurance and certifications

This website does not claim ISO, SOC 2 or independent penetration-test certification. Security assurance, privacy operations and contractual requirements should be assessed for the intended deployment.

Controls outside the current scope

Enterprise SAML/OIDC SSO, SCIM, custom field-level policies, malware scanning, automated retention, legal hold and centralised observability are not included in the current standard product. Review these needs during scoping.

Report a concern

Contact the UmiHR team through Qort Inc.’s corporate contact. Describe the affected area and the issue without sending passwords, private employee records or unnecessary sensitive details. The team can arrange an appropriate channel for further information.

sm@qort.com

Put the right controls around your people operations.

Tell us about your team, your current processes and the workflows you want to improve.

Request a demo