Security
Trust starts with clear choices
We record no more than we need and give people access that fits their role. Administration and medical information stay separate.
Design principles
These four principles guide the choices we make while building Absentra.
As little data as possible
Absentra focuses on administrative absence management without medical content, using only the data it needs.
Appropriate access
People should only see what fits their role and responsibility.
Separate environments
Demo and test data should stay technically separate from real data.
Auditability
Important changes and actions should be traceable where needed.
No medical records
Absentra has no fields for diagnoses, symptoms, treatments, medical notes or causes of illness.
What Absentra does record
- which employee it concerns
- start and end date
- administrative status
- department or team
- outstanding administrative actions
What Absentra does not record
- diagnosis
- symptom
- treatment
- medical note
- cause of illness
This is the current product scope, not a complete legal data list. Note: the administrative sick and recovery notifications that Absentra does record may qualify as data concerning health under the GDPR. We protect them accordingly and ask for no more than we need.
No claims without evidence
We only make security and compliance claims on this site if we can back them up. Anything still in development or under test is not presented as finished.
How the contact form is protected
The principles above describe the product we are building. These are measures already running on this website.
- Checks on the server: we match every request against a fixed schema and reject fields that do not belong there.
- Bot detection: Vercel BotID checks every submission before any email goes out.
- Origin checks: we only accept requests sent from this website.
- Honeypot and limits: we quietly ignore automated submissions and turn away oversized requests.
- Minimal logging: what you type never reaches the log files, and error messages carry no technical detail.
Responsible disclosure
Found a possible security issue in the website or the demo? Report it confidentially and we will pick it up as quickly as we can. Do not include employee data or other personal data in your report.
Email your report to contact@absentra.nl with the subject “Beveiligingsmelding Absentra”.
Questions about security or data processing?
Feel free to ask. We will tell you where Absentra stands today and what sits behind these choices.