1.Overview and Scope
This Security Exhibit describes BambooHR's technical and organisational security measures ("Security Measures") designed to protect Customer Data against unauthorized access, disclosure, alteration, and destruction. This Exhibit is incorporated into and forms part of the BambooHR Data Processing Agreement.
BambooHR is certified under the SOC 2 Type II framework (AICPA Trust Services Criteria for Security, Availability, and Confidentiality) and undergoes annual third-party audits to verify the design and operating effectiveness of these controls. Customers may request a copy of BambooHR's most recent SOC 2 report under NDA by contacting our security team via our contact page.
2.Infrastructure and Network Security
BambooHR's production infrastructure is hosted on Amazon Web Services (AWS) in the United States, with data replicated to multiple availability zones for redundancy. All production systems are isolated in a Virtual Private Cloud (VPC) with strict network access controls. BambooHR employs firewalls, intrusion detection systems, and web application firewalls to protect against unauthorized access and common web-based attacks.
BambooHR uses a defence-in-depth approach to network security, including network segmentation between production, staging, and development environments; automated vulnerability scanning of infrastructure components; and continuous monitoring of network traffic for anomalous activity.
3.Data Security and Encryption
All Customer Data is encrypted in transit using TLS 1.2 or higher. All Customer Data at rest is encrypted using AES-256 encryption. Database encryption keys are managed using AWS Key Management Service (KMS) with strict access controls and rotation policies.
Customer Data is logically segregated from data belonging to other customers through application-level and database-level controls. BambooHR performs regular data classification exercises to identify and apply appropriate security controls to different categories of data.
4.Application Security
BambooHR follows a secure software development lifecycle (SSDLC) that includes security requirements definition, threat modelling, code review for security vulnerabilities, and security testing. All code changes are reviewed by at least one engineer before deployment, and changes are subject to automated security scanning.
BambooHR conducts annual penetration testing performed by an independent third-party security firm. Critical and high-severity findings are remediated within defined SLAs. BambooHR also operates a vulnerability disclosure programme that allows external researchers to report potential security issues.
5.Access Controls and Authentication
Access to production systems is restricted to authorised BambooHR personnel on a need-to-know, least-privilege basis. All access to production environments requires multi-factor authentication (MFA) and is logged and audited. Privileged access is reviewed quarterly and revoked immediately upon employee termination.
Customers can configure multi-factor authentication, single sign-on (SSO), and role-based access controls (RBAC) within their BambooHR accounts. BambooHR supports SAML 2.0-based SSO integration with major identity providers including Okta, Azure AD, and Google Workspace.
6.Incident Detection and Response
BambooHR maintains a documented Security Incident Response Plan that defines procedures for detecting, classifying, containing, investigating, and recovering from security incidents. The incident response team includes representatives from security, engineering, legal, and customer support functions.
BambooHR uses a combination of automated alerting and 24/7 on-call security monitoring to detect potential security incidents. Upon confirming a security incident affecting Customer Data, BambooHR will notify affected customers within seventy-two (72) hours as required by applicable law and the Data Processing Agreement.
7.Business Continuity and Disaster Recovery
BambooHR maintains a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) that are tested at least annually. BambooHR targets a Recovery Time Objective (RTO) of four (4) hours and a Recovery Point Objective (RPO) of one (1) hour for its core platform services.
Customer Data is backed up continuously using point-in-time recovery and daily snapshots retained for thirty (30) days. Backup integrity is tested regularly to ensure data can be successfully restored in a recovery scenario.
8.Employee Security and Training
All BambooHR employees with access to production systems or Customer Data undergo background checks prior to employment and sign confidentiality agreements. All employees complete mandatory security awareness training upon hire and annually thereafter, covering topics including phishing awareness, password hygiene, and data handling responsibilities.
BambooHR has a documented acceptable use policy for employees and contractors that prohibits use of BambooHR systems for personal activities and unauthorized data access. Violations are subject to disciplinary action up to and including termination.








































