TRUST

Security at shiftfloor.

Privacy isn't a feature here — it's the architecture. This page explains, in plain words, how we keep every team's day its own.

Per-team access.

Each team operates behind its own private key. There are no shared logins and no public pages — and access for any team can be rotated instantly, invalidating the previous key on the spot.

Data minimalism.

We store only what a working day needs: first names, shifts and assignments. No contact details, no pay data, nothing sensitive by design.

Encrypted in transit.

All traffic is encrypted in transit (TLS), data is isolated per team, and every read and write is verified against that team's key — on every request.

See something off?

Tell us and we'll answer fast: hello@shiftfloor.com. We take every report seriously, from anyone.