Security
Trust starts with clear choices
Absentra is developed around data minimization, appropriate access and a clear separation between administrative and medical information.
Design principles
These principles guide the choices made during the development of Absentra.
Data minimization
Absentra focuses on the non-medical data needed for administrative absence registration and follow-up.
Appropriate access
Users should only get access to the data and features that match their role and responsibility.
Separated environments
Demo, test and production data should remain technically separated from each other.
Auditability
Important changes and actions should be auditable where needed.
No medical records
Absentra is not intended for diagnoses, medical complaints, treatments, medical notes or causes of illness.
Within the administrative scope
- employee
- start and end date
- administrative status
- department or team
- outstanding administrative actions
Not within the scope
- diagnosis
- medical complaint
- treatment
- medical note
- cause of illness
This overview describes the current product scope of Absentra, not a complete legal data list.
No claims without substantiation
Absentra only publishes security and compliance claims that can be demonstrably substantiated. Measures that are still being developed or validated are not presented as completed.
How the contact form is protected
Unlike the design principles above, these are measures implemented on the current website.
- Server-side validation: every request is checked on the server with a strict schema; unknown fields are rejected.
- Bot detection: Vercel BotID checks every submission before any email is sent.
- Origin checks: only requests sent from our own website are accepted.
- Honeypot and request limits: automated submissions are silently ignored and oversized requests are rejected.
- Minimal logging: the contents of the form are never logged and error messages contain no technical details.
Responsible disclosure
Found a (potential) security issue in the website or the demo? Report it confidentially and we will follow up as quickly as possible. Do not include sensitive employee data or other personal data in your report.
Email your report to info@absentra.nl with the subject “Beveiligingsmelding Absentra”.
Questions about security or data processing?
Get in touch for an explanation of the current product status and the principles behind Absentra.