Trust · Security

Security posture

The practices listed below are in place today and verifiable in the site's codebase. We list practices, not certifications.

  • Every response from the public site carries Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers.

    Status: current · Last reviewed 2026-07-28

  • Visitor IP addresses are stored only as salted SHA-256 hashes, with a separate derived salt per surface, so commercial-funnel and CHAP activity cannot be correlated by IP.

    Status: current · Last reviewed 2026-07-31

  • Endpoints that store visitor data fail closed: the demo request and CHAP APIs return 503 rather than operate without the IP-hashing salt configured.

    Status: current · Last reviewed 2026-07-31

  • Internal routes are gated by credentials compared in constant time, and return 503 rather than serve when the secret is not configured.

    Status: current · Last reviewed 2026-07-31

  • Production, preview, and development run against separate databases; preview and development environments hold no production data.

    Status: current · Last reviewed 2026-07-31

  • Funnel analytics are first-party, server-side event records only. The site sets no analytics or tracking cookies; the only cookie is an HTTP-only resume token for the discovery questionnaire, which contains no identifiers.

    Status: current · Last reviewed 2026-07-31

  • CHAP AI on this site answers questions for information only: it takes no action on any payroll system and writes nothing beyond its own interaction log.

    Status: current · Last reviewed 2026-07-31

  • Every citation CHAP returns must resolve to a corpus of verbatim primary-source excerpts. The server rejects responses citing outside that corpus, and a mechanical verifier checks the corpus text against its sources.

    Status: current · Last reviewed 2026-07-31

  • The public site ships no third-party analytics or advertising scripts.

    Status: current · Last reviewed 2026-07-30

  • Dedicated trust and security contact addresses monitored by PSE.

    Status: current · Last reviewed 2026-07-31

Contact

trust@payrollsynergyexperts.com

security@payrollsynergyexperts.com