⚙️ How Data is Secured in Hera
Hera is hosted on Amazon Web Services (AWS), which provides industry-leading infrastructure security.
All data is stored using AWS S3, which includes:
Encryption at rest and in transit
Strict access controls
Modern cloud security best practices
Our infrastructure is secure and routinely reviewed for improvements.
❌ Storing Highly Sensitive Data
While Hera is built with security in mind, we do not currently recommend storing highly sensitive personal information such as:
Social Security Numbers (SSNs)
Government-issued IDs (e.g., Driver’s Licenses)
Medical or protected health information (PHI)
This type of information is best managed by platforms that have completed formal SOC 2 or SOC 3 audits, such as your payroll/HR system (e.g., ADP, Paycom, etc.).
✅ What Are Some Alternatives?
If you need to manage highly sensitive files outside of Hera, we suggest:
Using secure cloud storage platforms that support strong password protection and granular sharing controls
Storing files on encrypted or password-protected local devices if offline access is required
Ensuring access is limited to only those who require the information to perform their job
🔐 Restricting Access to Documents in Hera
Hera supports per-user permission settings, allowing you to limit document access on a need-to-know basis.
To configure this:
Go to the Users section
Select the user you want to update
Turn off "Full Admin Access"—this is required to expose granular permission controls
Scroll down to the Permissions section
Toggle "Associate Management: Associate Documents" on/off as needed
Screenshot example:
Only users with this permission will be able to view, upload, or delete Associate documents.
Important: If a user has Full Admin Access enabled, they will have access to all documents by default.
To enable document-specific restrictions, you must disable Full Admin Access first. This will unlock the ability to customize individual permissions.
💬 Final Thought
We recommend having an internal discussion to define how your team handles sensitive HR data, who needs access, and what tools are best aligned with your compliance and privacy goals.
Hera supports secure operations, but it's most effective when paired with intentional data management practices.