Separation by organisation
Belonging to an organisation is a structural condition of data access: every database is distinct from the others, and a request that doesn't identify it correctly returns nothing.
We don't have security certifications to show, and there's no access request to fill in before you can read anything. What we actually do is written on this page and in the linked legal documents, public and readable right now: where the data lives, how it's protected, what the AI does and doesn't do.
Each organisation's database is hosted in the European Union. The rest of the infrastructure, and its providers, are described below.
Each organisation has its own database, separate from every other, hosted in the European Union, in the Frankfurt region.
The application and the functions that process requests are hosted by a United States provider, with the European Union's standard contractual clauses as the basis for the transfer.
Sick notes uploaded by employees are stored encrypted, with 256-bit AES encryption.
Every provider that processes data on your behalf is appointed as a data processor, with its function and place of processing published.
We don't have an ISO or SOC certification to show. The measures below are the ones described in the data processing agreement, not a separate list written just for this page.
Belonging to an organisation is a structural condition of data access: every database is distinct from the others, and a request that doesn't identify it correctly returns nothing.
Data in transit travels over TLS-protected connections; data at rest is encrypted according to the guarantees of the infrastructure providers.
Every access is personal, with permissions that differ between employee and administrator. No shared accounts.
An account that receives a series of failed login attempts is temporarily locked, with a lockout that lengthens if attempts continue; beyond a high number of attempts the lockout becomes permanent and needs an administrator to remove it.
Administrative operations on the data are logged, so who did what can be reconstructed.
Backups are managed by the database provider, with automatic rotation.
Qualys SSL Labs rates the TLS configuration of leavepilot.app A+, detected on 21 August 2026. See the SSL Labs report
The commentary that accompanies reports is generated by artificial intelligence, but it only works on numbers that are already aggregated: counts, averages, breakdowns by department.
It never receives names, email addresses, or rows tied to a single person: departments too small to stay anonymous don't appear as a separate line.
All the technical details, automatic checks and usage limits are in the instructions for use, public like every other document.
All legal documents are public and versioned: no access request, no waiting.
The database is hosted in the European Union, in the Frankfurt region, in a separate database for each organisation. The application and the functions that run it are hosted by a United States provider; uploaded sick notes are encrypted with 256-bit AES.