Export
Owners can export payroll summaries and detailed timesheet records.
Concrete information about the controls currently used by NEO Workforce, including what we do not claim.
NEO Workforce's public website and operational web app are served over HTTPS/TLS, which encrypts browser traffic in transit between the device and the service.
We do not currently publish a claim that all stored application data is encrypted at rest because we have not independently verified and documented that implementation for customers.
Operational workforce data is accessed through authenticated accounts. Backend data operations are scoped to the authenticated account's workspace rather than exposing a shared public workforce database.
Management functions use a separate 4-digit Owner PIN. Employees use individual 4-digit clock PINs for clock actions on the workplace device.
Clock-in, clock-out and break records are stored as structured shift data. When an owner corrects a genuine clocking error, NEO Workforce can preserve the original value and the edit timestamp so the correction remains visible for accountability.
Offline clock actions are queued locally on the workplace device and synchronised when internet access returns. Pending records are protected from being overwritten by a server reload while they remain unsynchronised.
Owners can export payroll summaries and detailed timesheet records.
Owner Mode includes a permanent workforce-data deletion control protected by the Owner PIN.
Owner-only controls are separated from the normal staff clock interface and shared-device Standby mode.
Subscription payments are handled through Stripe. NEO Workforce does not need to store customers' full payment-card details in the workforce application.
The service also relies on infrastructure and authentication providers required to host and operate the application. These providers may process service data as described in the Privacy Policy and Data Processing Terms.
NEO Workforce does not currently claim ISO 27001 certification, SOC 2 certification, penetration-test certification or an independent third-party security audit. If that changes, this page will be updated with the specific scope and evidence.
Being transparent about the controls we have — and the assurance we do not yet have — is preferable to making broad security claims that cannot be substantiated.
If you believe you have found a security issue, contact hello@neoworkforce.co.uk with enough detail for the issue to be investigated. Do not include unnecessary employee personal data in the report.