1. Access control
- Role-based permissions can limit access to administrative and operational functions.
- User-level permission controls can support more specific responsibilities where configured.
- Password recovery and account administration should be limited to authorized users.
2. Attendance verification
Depending on configuration, attendance can use time-bound QR sessions, location validation, trusted-device context, fingerprint verification on supported mobile devices, or compatible biometric attendance devices. A QR code by itself is not intended to be the only identity signal in a configured QR + fingerprint workflow.
3. Auditability and logs
EkamQR includes operational logs and audit-oriented records for areas such as attendance events, device communication and administrative activity. Available detail varies by module and deployment.
4. Data protection
Internet-facing deployments should use HTTPS/TLS. Access to workforce, payroll and attendance data should be restricted to authorized roles. Backup, retention and deletion procedures should be defined for each deployment. EkamQR does not claim that any technical system can eliminate all security risk.
5. Deployment models
EkamQR can be deployed in environments with different infrastructure and access requirements. Security responsibilities vary between cloud, on-premise, Windows and Linux deployments, especially for operating-system hardening, network controls, database access, backups and endpoint security.
6. Customer responsibilities
- Protect administrator accounts and credentials.
- Keep host operating systems, browsers and supported mobile devices updated.
- Restrict database and server access.
- Use appropriate employee notices and legal basis for biometric and location processing.
- Review connected biometric-device compatibility before production rollout.
7. Incident handling
Security concerns should be reported promptly with the affected organization, approximate time, observed behavior and non-sensitive diagnostic details. Do not send passwords, private keys or full biometric data by email.
8. Security assessments and questionnaires
Organizations with procurement or compliance requirements may request additional security information. Detailed questionnaire responses and evidence are provided as appropriate for the customer and deployment rather than publishing sensitive operational details publicly.
Email hello@ekamqr.com and include the organization name and assessment scope.
