apronly.
Behind every shift.
Security at a glance
v1.0 · 21 May 2026
How apronly protects your business
👤
Biometric unlock. Optional Face ID / Touch ID / Windows Hello via WebAuthn + PRF. The encrypted password is locked to a per-device key that only your biometric can reveal — no PIN to type, no code to copy.
🔑
Two-factor authentication. Optional TOTP (Google Authenticator / Authy / 1Password / Microsoft Authenticator). Required at sign-in when enabled. Biometric unlock satisfies 2FA on its own (no double prompt).
🔐
Zero-knowledge vault. Passwords are encrypted on your device with AES-256-GCM before they reach our servers. PBKDF2 600,000 rounds (OWASP 2023). We can't read them — even with full database access.
✍️
Tamper-evident signatures. Every signed document gets a SHA-256 fingerprint bound to the signer, IP, user-agent, and timestamp. Any later edit invalidates the signature. Recognised as eIDAS Advanced Electronic Signatures.
🛡
Per-company isolation. Postgres row-level security enforces tenant boundaries on every query — server-side, not in the app. A tampered client can't bypass it.
📜
Auditable end-to-end. Every sensitive action — vault unlocks, reads, copies, edits, signatures — is logged with actor + timestamp. Owner-readable; never the value itself.
Regulatory alignment
GDPR · EU 2016/679 — full data subject rights (access, rectify, erase, restrict, port, object) · 72-hour breach notification · DPA available. · eIDAS · EU 910/2014 — Advanced Electronic Signatures, legally recognised EU-wide. · Codul Muncii · RO Labour Code — leave documents in ITM-expected format, working-time rules in the rota planner.