apronly.

Behind every shift.

Security at a glance
v1.0 · 21 May 2026

How apronly protects your business

👤 Biometric unlock. Optional Face ID / Touch ID / Windows Hello via WebAuthn + PRF. The encrypted password is locked to a per-device key that only your biometric can reveal — no PIN to type, no code to copy.
🔑 Two-factor authentication. Optional TOTP (Google Authenticator / Authy / 1Password / Microsoft Authenticator). Required at sign-in when enabled. Biometric unlock satisfies 2FA on its own (no double prompt).
🔐 Zero-knowledge vault. Passwords are encrypted on your device with AES-256-GCM before they reach our servers. PBKDF2 600,000 rounds (OWASP 2023). We can't read them — even with full database access.
✍️ Tamper-evident signatures. Every signed document gets a SHA-256 fingerprint bound to the signer, IP, user-agent, and timestamp. Any later edit invalidates the signature. Recognised as eIDAS Advanced Electronic Signatures.
🛡 Per-company isolation. Postgres row-level security enforces tenant boundaries on every query — server-side, not in the app. A tampered client can't bypass it.
📜 Auditable end-to-end. Every sensitive action — vault unlocks, reads, copies, edits, signatures — is logged with actor + timestamp. Owner-readable; never the value itself.
Regulatory alignment

GDPR · EU 2016/679 — full data subject rights (access, rectify, erase, restrict, port, object) · 72-hour breach notification · DPA available.  ·  eIDAS · EU 910/2014 — Advanced Electronic Signatures, legally recognised EU-wide.  ·  Codul Muncii · RO Labour Code — leave documents in ITM-expected format, working-time rules in the rota planner.

apronly · Data Processing Agreement available on request
Full one-pager: apronly.app/trust-onepager.html