Compliance

HR compliance built into the platform.

Employee files, payroll, and hiring data are some of the most sensitive records a company holds. Otto HR makes protecting them the default: tenant isolation enforced at the database, consent captured where data is collected, and a full audit trail. It is not an afterthought your team has to police.

RLS

Tenant isolation enforced in the database

KVKK

Turkish data protection, built in

AES-256

Encryption for stored integration tokens

Why Otto

Security as the default, not an add-on.

01

Tenant isolation by default

Every record is scoped to your company at the database layer with row-level security, so isolation is enforced by Postgres itself, not by application code that can forget.

02

Consent at the point of collection

Candidates and new hires see the right privacy notices and give explicit consent exactly where their data enters the system, with the accepted versions recorded.

03

Role-based access

HR, managers, and employees each see only what their role allows. Employees manage their own data in the portal without seeing anyone else's.

How it works

Protection at every layer of the stack.

Isolate

One company, one boundary

Multi-tenancy is enforced with Postgres row-level security: every table is scoped to your company, and the database itself rejects cross-tenant reads and writes, so even a bug in the app can't leak another company's data.

Isolate

Row-level security

select * from employees

Acme Ltd · your company

26 rows

Allowed

Another company

0 rows

Blocked

The boundary is in the database, not the app.

Consent

Notices and consent where data is collected

Job applications show the equal-opportunity notice and privacy policy. Turkish companies additionally get the candidate Aydınlatma Metni and KVKK explicit consent in the same flow. Pre-boarding captures the employee-facing consent pair before day one.

Consent
EnTr

Aydın Tekstil

Tekstil · 120 çalışan

Açık pozisyonlar

Satış Uzmanı

İstanbul · Tam zamanlı

Frontend Geliştirici

Uzaktan · Tam zamanlı

Başvuru · Satış Uzmanı

Aydınlatma Metni

Gizlilik bildirimini okudum ve onaylıyorum

Başvur
Audit

A record of every sensitive action

Otto keeps an audit log of security-relevant changes across the platform, and demo or preview sessions are hard-blocked from writing at the database layer, so your real records stay clean.

Audit

Audit log

Last 24 hours

leave_balance.adjusted

James Cole · Sarah Kim · +2 days

09:14

employee.deactivated

Selin Acar · Tom Weber

11:02

mcp.tool_called

Agent · listEmployees

11:40
AI

AI that respects the boundary

AI features run on a metered, auditable pipeline. Candidate-supplied text is delimited as untrusted before models see it, and person-level data is stripped from documents like insurance policies before parsing.

AI

Your AI agent

/api/mcp/hr
listEmployees()
Scope: HR · role checked
Row-level security applied
Metered and audit-logged
200 OK26 employees returned

Frequently asked questions

Otto HR is built to support your KVKK obligations: aydınlatma metni acknowledgments, explicit consent capture (including Article 9 cross-border consent), consent records, and Turkish-language legal texts. Your company remains the data controller, and Otto gives you the tooling to meet the obligations.

Otto follows GDPR-aligned practices: consent at collection, role-based access, minimization of data sent to AI models, and audit logging. EU/EEA signups are handled with additional care at registration.

Access is role-based. HR roles manage company records, managers see their scope, and employees see and manage only their own data in the self-service portal, enforced by database policies rather than just the UI.

Only what a feature strictly needs. Person-level data is redacted from parsed documents before any model call, employee names in reconciliation stay out of prompts, and candidate-authored text is treated as untrusted input.

The privacy policy, visitor aydınlatma metni, and membership agreement are published on this site and linked from the footer, and Turkish companies get candidate- and employee-facing KVKK texts inside the product flows.

Compliance without the busywork

Protect your people's data by default.

Create a workspace and see how consent, access control, and audit logging work when they're built in.