Security & privacy

Workforce access with boundaries built in.

EscoHR's product design connects to Escochex Payroll for identity and role context, requests sensitive device permissions only when they are relevant, and keeps private workflows scoped to authorized participants.

01

Escochex-managed identity

Sign-in uses existing Escochex Payroll credentials. Company access and assigned roles are resolved from Escochex rather than created inside EscoHR.

02

Session verification

New authenticated sessions include a one-time verification code, with resend, expiry and failed-attempt states in the product flow.

03

Device re-entry

A valid session can be unlocked using supported device security such as Face ID or a device PIN without selecting a different role.

04

Event-based location

Location is requested for attendance events to confirm a worksite or approved remote location. The product design explicitly rejects continuous location tracking.

05

Just-in-time attachments

Camera or file access is requested when an employee chooses to attach content to a supported workflow, not as background access.

06

Private HR cases

Employee cases are scoped to the reporter and the assigned authorized HR Admin, with reassignment and resolution history preserved.

Sensitive notifications

Useful alerts without exposing the case on the lock screen.

The product design uses general notification wording for sensitive updates, then deep-links the authenticated user to the authoritative record inside EscoHR.

Schedule updatesApprovalsAttendance remindersCase updatesCompany notices
Access follows the workspace.

If a user's Escochex role or company access changes, EscoHR requires refreshed authentication instead of continuing with stale permissions.

Transparency

Read how EscoHR handles personal information.

The Privacy Policy distinguishes employer-controlled workforce data from app operations and explains location, attachments, notifications, access, retention and privacy requests.