Compliance
HR compliance built into the platform.
Employee files, payroll, and hiring data are some of the most sensitive records a company holds. Otto HR makes protecting them the default — tenant isolation enforced at the database, consent captured where data is collected, and a full audit trail — not an afterthought your team has to police.
RLS
Tenant isolation enforced in the database
KVKK
Turkish data protection, built in
AES-256
Encryption for stored integration tokens
Why Otto
Security as the default, not an add-on.
Tenant isolation by default
Every record is scoped to your company at the database layer with row-level security — isolation is enforced by Postgres itself, not by application code that can forget.
Consent at the point of collection
Candidates and new hires see the right privacy notices and give explicit consent exactly where their data enters the system — with the accepted versions recorded.
Role-based access
HR, managers, and employees each see only what their role allows. Employees manage their own data in the portal without seeing anyone else's.
How it works
Protection at every layer of the stack.
One company, one boundary
Multi-tenancy is enforced with Postgres row-level security: every table is scoped to your company, and the database itself rejects cross-tenant reads and writes — even a bug in the app can't leak another company's data.
Company overview
This monthNotices and consent where data is collected
Job applications show the equal-opportunity notice and privacy policy; Turkish companies additionally get the candidate Aydınlatma Metni and KVKK explicit consent in the same flow. Pre-boarding captures the employee-facing consent pair before day one.
Alex Morgan
Product Designer · day one
Sign employment contract
HR · e-signature
Upload ID & bank details
Employee
Set up laptop & accounts
IT
Intro meeting with the team
Manager
A record of every sensitive action
Otto keeps an audit log of security-relevant changes across the platform, and demo or preview sessions are hard-blocked from writing at the database layer — so your real records stay clean.
Selin Acar
Software Engineer
Department
Engineering
Start date
Mar 3, 2026
Manager
James Cole
Location
Istanbul
AI that respects the boundary
AI features run on a metered, auditable pipeline. Candidate-supplied text is delimited as untrusted before models see it, and person-level data is stripped from documents like insurance policies before parsing.
How many vacation days does Deniz have left?
Frequently asked questions
Otto HR is built to support your KVKK obligations: aydınlatma metni acknowledgments, explicit consent capture (including Article 9 cross-border consent), consent records, and Turkish-language legal texts. Your company remains the data controller — Otto gives you the tooling to meet the obligations.
Otto follows GDPR-aligned practices: consent at collection, role-based access, minimization of data sent to AI models, and audit logging. EU/EEA signups are handled with additional care at registration.
Access is role-based. HR roles manage company records, managers see their scope, and employees see and manage only their own data in the self-service portal — enforced by database policies, not just the UI.
Only what a feature strictly needs. Person-level data is redacted from parsed documents before any model call, employee names in reconciliation stay out of prompts, and candidate-authored text is treated as untrusted input.
The privacy policy, visitor aydınlatma metni, and membership agreement are published on this site and linked from the footer — and Turkish companies get candidate- and employee-facing KVKK texts inside the product flows.
Compliance without the busywork
Protect your people's data by default.
Start with a 30-day Pro trial and see how consent, access control, and audit logging work when they're built in.