PHELTIX

Legal & trust

Security

PHELTIX is designed for controlled workforce attendance deployments where organization separation, role-based access, device binding, and auditability matter.

Last reviewed: 11 June 2026

Trust notes

Organization isolation
Role-based access
Audit-oriented logging

1. Core principles

  • Organization isolation: customer data is scoped by organization.
  • Least privilege: users only receive the access required for their role.
  • Auditability: attendance, corrections, exports, and admin actions are designed to be reviewable.
  • Secure rollout: Starter uses GPS geofencing, device binding, random selfie audits, and offline punch sync; Pro adds BLE/iBeacon proof of presence.

2. Access control

  • Authentication-backed dashboard and mobile access.
  • Role-aware permissions for owner, admin, manager, and employee users.
  • Employee users should not access administrative controls.
  • Device binding helps reduce account sharing and buddy punching.
  • Backend access controls and validation are used to reduce cross-tenant access risk.

3. Super-admin access disclosure

Authorized PHELTIX personnel may access customer data only where necessary to provide, support, secure, troubleshoot, maintain, or improve the services; respond to support requests; investigate abuse or security incidents; comply with legal obligations; or manage billing and account administration.

Super-admin access is not for casual browsing. Access should be restricted, reviewed, and used only for legitimate operational purposes.

4. Attendance verification controls

  • GPS geofence validation for location-based punch checks.
  • GPS degraded-mode review where GPS signals are unreliable or inconsistent.
  • Optional random selfie audits where enabled by the customer.
  • Pro BLE/iBeacon validation for stronger proof of presence.
  • Offline punch queueing with later sync when the device reconnects.

5. Data protection measures

  • Role and organization-scoped access patterns.
  • Security-focused access controls and backend validation.
  • Audit-oriented event logging for important operational changes.
  • Controlled support access for troubleshooting and client assistance.
  • Subprocessor review through the public Subprocessors page.

6. Reporting security concerns

Report suspected vulnerabilities, unauthorized access, or security concerns to support@pheltix.com. Please do not include unnecessary employee personal data in security reports.