Skip to content
Anstell
Security

Salary data, handled like salary data.

Anstell holds what people earn, where they live and when they were born. This page says plainly what we do with it.

Where the data lives

Payroll and employee records are held in a Postgres database in the EU. Backups are taken daily and retained for 30 days. Nothing is replicated outside the EU or Switzerland.

Who can reach it

Every record belongs to exactly one client organization, and every query is filtered by it at the application boundary rather than by convention. Anstell staff access is role-based and logged.

In transit

TLS 1.3 everywhere, HSTS on every domain. Session cookies are HttpOnly, Secure and SameSite-scoped. There is no API key that grants cross-organization access.

Passwords

Hashed with scrypt, never reversible, never logged. Password reset uses a single-use token that expires in one hour.

What we do not collect

No behavioural tracking on the portal. No third-party analytics script on any page that displays salary data. No advertising pixels anywhere.

When you leave

Employment records are retained for ten years, because Swiss law requires it of an employer. Everything not covered by that obligation is deleted within 30 days of your request.

Found a vulnerability? Tell us through the contact form and mark it as a security report. We reply within two working days and will not pursue anyone who reports in good faith.