Payroll data is some of the most sensitive data a business holds. This page describes the technical and organisational measures we use to protect it. For contractual terms, see our Data Processing Agreement and Privacy Policy.
Infrastructure and data location
- Production systems and databases are hosted in the European Union (Amsterdam, Netherlands), a jurisdiction covered by the UK adequacy regulations.
- Production services use fixed egress IP addresses, so third parties we connect to (such as HMRC and accounting platforms) can verify traffic originates from us.
- Production, staging, and development environments are fully segregated. Customer data is never used in development environments.
Encryption
- All data in transit is encrypted with TLS.
- Data at rest, including databases and backups, is encrypted.
- Credentials, API keys, and integration secrets are stored as managed environment secrets, never in source code.
Access control
- Customer accounts support multi-factor authentication.
- Internal access to production systems is limited to named engineers on a least-privilege basis, protected by MFA.
- Role-based permissions in the platform let employers and accountants control who can view and run payroll.
Resilience and monitoring
- Databases are backed up automatically on a regular schedule, with encrypted backups.
- Production systems are monitored and logged; errors are tracked and triaged continuously.
- Payroll submissions to HMRC are queued and retried safely, so transient failures do not lose data.
Data protection
- Moonworkers Ltd is registered with the Information Commissioner’s Office (ICO) and pays the annual data protection fee.
- We process payroll data as a processor under a Data Processing Agreement that forms part of our Terms of Use.
- Sub-processors are listed in the DPA and bound by equivalent data protection obligations.
- We support data subject rights requests and provide full payroll data exports on account closure.
Certifications and roadmap
Moonworkers is HMRC-recognised payroll software. We do not currently hold ISO 27001 or SOC 2 certification. We are working towards Cyber Essentials certification as a first formal milestone, and ISO 27001 is on our longer-term roadmap as the business scales. We are happy to complete security questionnaires and walk partners through our architecture on request.
Reporting a security concern
If you believe you have found a vulnerability in any Moonworkers service, please contact us at privacy@moonworkers.co.uk with enough detail for us to reproduce the issue. We will acknowledge your report promptly and keep you informed as we investigate.