SOC2C

Is this your company? Buyers are checking Humanforce here. Claim humanforce.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Humanforce logo

Humanforce

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Humanforce is SOC 2 Type II compliant. Humanforce also holds ISO 27001, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

At Humanforce, your trust is our top priority. We understand the significance of data security in today's digital landscape and are dedicated to safeguarding your data with the utmost care. Our commitment to security is unwavering, and we employ comprehensive systems and protocols to ensure the protection of the information you entrust to us. This commitment spans our entire Human Capital Management (HCM) suite, including Workforce Management (WFM), HR (formerly IntelliHR), Benefits (formerly Thrive), and Talent (formerly LiveHire). These robust security measures are designed to safeguard the

Compliance & infrastructure

Hosting
AWS

Subprocessors

37
  • A
    Amazon Web Services · Cloud provider
    Australia, Ireland, USA
  • M
    Microsoft Office 365 · Document management
    Austalia
  • A
    Atlassian Cloud · Collaboration
    Australia
  • S
    Slack · Collaboration
    Australia
  • A
    Amplitude · Data analytics
    USA
  • C
    Captivate IQ · Sales commission software
    USA
  • A
    Asana · Collaboration
    USA
  • B
    Brain Payroll UK Limited · Payroll
    UK
  • E
    Emapta · Customer support
    Philippines
  • F
    Figma · Product and design
    USA
  • H
    Hubspot · Marketing
    USA
  • I
    Intercom · Customer support
    Australia (US and Ireland regions available)
Show all 37 subprocessors
  • M
    Mavenlink (now Kantata) · Professional services
    USA
  • M
    Maxio LLC (Formely Chargify LLC) · Subscription management
    USA
  • P
    PandaDoc · Document management
    USA
  • P
    Payroll Metrics · Payroll
    Australia
  • S
    Streamkap · Data replication
    USA
  • T
    Thoughtspot · Data Analytics
    USA
  • T
    Tomorrow's People · Professional services
    Australia and New Zealand
  • X
    Xero · Finance and payments
    USA
  • Z
    Zapier · Collaboration
    USA
  • Z
    Zendesk · Customer Support and help desk
    USA
  • P
    Pinpoint · Professional services
    Australia
  • P
    Productboard · Product and design
    USA
  • C
    Cintra HR & Payroll Services Limited · Professional services
    Ireland (EU)
  • S
    Sugar CRM · Sales
    USA
  • S
    SuperAPI · Collection and verification of Superannuation
    Australia
  • S
    Stream · Chats & Messaging within WFM product
  • E
    Elephant Group · Professional services
    Australia, New Zealand & UK
  • W
    WalkMe · Digital adoption analytics and workflow engagement
    USA
  • G
    Gainsight · Customer Relationship, support and analytics services
    USA
  • S
    Segment · Data analytics
    USA
  • S
    SolvedBy.Ai · Data analytics
  • H
    Humanforce Holdings Pty Ltd (ABN 97 618 020 401) Australian parent company · Customer Support
    Australia
  • T
    TimeTarget Pty Limited (ACN 140 620 248) · Customer Support
    Australia, USA
  • T
    TimeTarget Workforce Management Limited (Company Number 09246413) · Customer Support
    UK
  • T
    TimeTarget Workforce Management Limited (NZBN 9429047051393) · Customer Support
    New Zealand

Compliance leadership

The person who leads Humanforce's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Humanforce's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Humanforce SOC 2 compliant?
Humanforce is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Humanforce ISO 27001 certified?
According to Humanforce's public trust center, Humanforce is ISO 27001 certified. On SOC2C this listing is Listed.
Is Humanforce GDPR compliant?
According to Humanforce's public trust center, Humanforce is GDPR compliant. On SOC2C this listing is Listed.
Is Humanforce SOC 2 Type I or Type II?
Humanforce is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Humanforce's SOC 2 for a vendor risk assessment?
Yes. Humanforce's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Humanforce

Reproduced from Humanforce's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What security certifications does Humanforce hold?
Humanforce is certified for both ISO 27001 and SOC 2 Type II, demonstrating our commitment to implementing and maintaining robust information security management systems and adhering to global standards for data security, privacy, and operational integrity.
Can customers perform their own vulnerability scans or penetration testing on Humanforce environments?
No. Humanforce does not permit customers to run vulnerability scans or penetration tests against our environments. Our infrastructure is shared across customers, and unauthorised scanning can impact performance, trigger security alerts, and lead to inaccurate results. We already conduct regular penetration testing and vulnerability scanning in a controlled and isolated manner, including: - External third-party penetration tests with code-assisted reviews - Continuous internal vulnerability assessments - Annual independent security audits aligned with our compliance frameworks For customers who require assurance, detailed reports and summaries are available through the Humanforce Trust Centre.
How does Humanforce manage data security?
Humanforce employs a multi-layered approach to data security, including: - ISO 27001 compliance: Ensuring a robust information security management system. - SOC 2 Type II compliance: Protecting data across key trust service principles. - Encryption: Data is encrypted both in transit and at rest. - Threat Monitoring: Continuous monitoring and threat detection systems. - Third-party Testing: Regular independent penetration tests.
What happens to customer data after the end of a contract?
Upon contract termination, Humanforce ensures: - Secure Data Deletion: Removing all data securely. - Processes align with applicable data protection regulations and contractual obligations.
How is facial recognition data handled?
Facial recognition feature is designed with privacy and security in mind. The following controls apply to the collection, processing, and storage of facial recognition data: - Facial analysis is primarily performed locally on trusted devices. Some facial processing may occur on Humanforce backend servers during administrative operations such as user migration. - Face registration data and images are stored in the customer’s SQL database and encrypted at rest. No facial recognition data is shared with any external party. - Anonymised facial vectors (not images) may be temporarily cached in the browser on trusted devices to support recognition. These vectors are ephemeral and not persisted on the server. - All data transmission between the front-end and back-end is encrypted in transit. - All associated facial recognition data is automatically deleted from the system upon employee termination.

Business & Industrial peers that completed SOC 2