Security by design
We treat security as part of product design and operations, not as a marketing add-on. We minimise the data required for each workflow and review access to sensitive functionality.
Security & Trust
RibiPeople is built to help companies run employee benefits, rewards and recognition across multiple markets. Our security approach focuses on reducing unnecessary data exposure, controlling access and using trusted infrastructure and service providers.
We treat security as part of product design and operations, not as a marketing add-on. We minimise the data required for each workflow and review access to sensitive functionality.
Access is designed around authenticated users and organisational permissions, helping keep employee and administrator experiences appropriately separated.
RibiPeople is intended to be served over encrypted HTTPS connections in production so information is protected while travelling between users and the platform.
We aim to collect and retain only the information reasonably needed to operate employee programmes, fulfil services, support users and meet legitimate business or legal requirements.
We design administrative workflows so sensitive programme actions can be controlled and reviewed. We investigate suspected misuse and can restrict access where needed to protect the service.
Where third-party providers help deliver hosting, communications, payments, rewards or fulfilment, we limit information sharing to what is reasonably necessary for the service being provided.
How we think about trust
We will not claim certifications or controls we have not completed. As our security programme and independent assurance mature, this page will be updated with verified details rather than badges for the sake of badges.
If your HR, IT, procurement or security team is evaluating RibiPeople, contact us for the current architecture, data-flow and vendor-security information we can provide for your review.
Contact our team →