Please access this document via the main proposal.

Return to proposal →

Infrastructure & Hosting

Enterprise-grade cloud infrastructure

The Peopletree platform runs entirely on Microsoft Azure. dfcu Bank's data is hosted in the EU, isolated from all other clients, and managed end-to-end by Peopletree - with zero infrastructure overhead for your IT team.

Hosting

Microsoft Azure - EU Region

All platform components run on Azure Germany West Central, within a private virtual network. No public-facing management ports are exposed.

  • Primary region: Azure Germany West Central
  • Multi-zone redundancy within primary region
  • Geo-redundant disaster recovery with point-in-time restore
  • 99.9% uptime SLA (Azure-backed)
  • Azure-managed geo-redundant backups
Architecture

Multi-tenant, isolated data

dfcu Bank operates in a logically isolated tenant environment. Your data is never commingled with other clients and access is strictly controlled at the tenant boundary.

  • Logical tenant isolation - dedicated database schemas
  • No cross-tenant data access
  • Containerised application deployment (Azure App Service)
  • Azure Application Gateway with WAF v2 (OWASP 3.2)
  • Network Security Groups with defined port allowlists
Authentication

SSO, MFA, and identity federation

The platform uses Auth0 for identity management, supporting SAML 2.0 and Microsoft Entra ID federation. dfcu Bank can integrate its existing identity provider with no additional tooling.

  • Auth0 - OIDC / JWT / SAML / ADFS
  • Microsoft Entra ID and ADFS / SAML 2.0 federation
  • MFA enforced; configurable per tenant
  • Role-based access control (RBAC)
  • VPN-gated admin access - no public management ports
  • Access revocation within 24 hours of termination
Data Security

Encryption and access controls

All data is encrypted at rest and in transit using FIPS 140-2 compliant standards. Production access is restricted to authorised Peopletree engineers, logged, and auditable.

  • AES-256 / FIPS 140-2 at rest (TDE on all SQL and MySQL)
  • TLS 1.2 minimum in transit on all connections
  • Azure Key Vault - dedicated per environment
  • Microsoft Defender for Cloud - real-time threat detection
  • Azure Monitor / Log Analytics - 90-day+ log retention
AI Processing

How TAILA handles dfcu Bank data

TAILA uses Azure OpenAI Service, hosted in the EU. All AI processing is stateless - no employee data is retained by the AI model, stored in training datasets, or used to improve the underlying model. Prompts contain only structured talent data; no personal or identifiable information is included.

Stateless Processing

Each AI interaction is processed independently. No conversation history, employee profiles, or assessment data is retained between sessions.

No Training on Client Data

dfcu Bank data is never used to train or fine-tune the underlying model. Microsoft's enterprise data protection commitments apply in full.

EU Region Only

All AI processing occurs within Azure Germany West Central. Data does not cross the EU boundary during AI processing.

Integrations & Data Governance

Connectivity and data handling

The platform integrates with any data source via REST API, SFTP, or direct database connection. dfcu Bank retains full ownership and control of all employee data throughout.

Peopletree builds and maintains the integration. dfcu Bank provides data access and an IT liaison contact. No ongoing maintenance is required from your team.

PayspaceSage VIPOracle Fusion SAP SuccessFactorsWorkdayAny HRIS via REST API

Transfer methods: REST API (HTTPS / TLS 1.2), Secure SFTP (TLS 1.2, key-pair auth), Azure ETL pipeline, or direct database integration on request.

ParameterDetail
Data ownershipdfcu Bank is data controller; Peopletree is data processor only
Tenant isolationLogical isolation per client; dedicated database schemas; no cross-tenant access
Data classificationFormal policy - confidential, internal, and public tiers
Data retentionDefined per contract; data purged on request within agreed SLA
Data residencyEU-based Azure data centre (Germany West Central); CDN edge nodes for static assets only
BackupAzure-managed geo-redundant; point-in-time restore available
GDPR / POPIAData Processing Agreement available; customer controls classification and retention
Uganda DPA 2019Platform architecture satisfies Uganda Data Protection and Privacy Act 2019 requirements - EU-compliant data residency, processor obligations, and consent management apply
AreaDetail
Change managementAll changes reviewed, tested, and approved before deployment; continuous vulnerability scanning; critical patches within 24 hours
Incident responseDocumented plan covering identification, containment, remediation, and communication; affected parties notified within agreed windows
Log retention90-day+ via Azure Monitor and Log Analytics Workspace
Business continuityDocumented BC/DR plan; geo-redundant storage with point-in-time restore; redundant infrastructure with Azure load balancing
Personnel securitySecurity awareness training and background checks for all staff; access revoked within 24 hours of termination
Vendor securityAll vendors assessed for security compliance before onboarding
Compliance & Certifications

Independently audited, annually

Full reports are available to dfcu Bank's IT and procurement teams under NDA. Contact Rob Heymann to initiate.

SOC 2 Type 2
Audited by Laika Compliance LLC under AICPA Trust Services Criteria. Controls for Security and Confidentiality were confirmed as suitably designed and operating effectively throughout the audit period. No significant incidents recorded.
Security & Confidentiality Laika Compliance LLC / AICPA Full report under NDA
Annual Penetration Test
Gray-box penetration test conducted annually by an independent third-party security firm. Coverage includes all web applications and APIs. All identified findings are remediated and validated before the report is closed.
All Findings Remediated Web Applications & APIs Executive summary under NDA
Roles & Responsibilities

What Peopletree manages vs what dfcu Bank controls

Area Peopletree Group dfcu Bank
Platform hosting and infrastructureFully managedNo action required
Security patching and updatesFully managedNo action required
WAF and network securityFully managed (Azure WAF v2)No action required
Backup and recoveryAutomated geo-redundant backupsNo action required
User access provisioningManaged via admin portalHR admin approves user requests
SSO / identity integrationConfigures SAML / Auth0 connectionProvides IdP metadata and IT liaison
HRIS / payroll data integrationBuilds and maintains integrationProvides data access and IT liaison
Data ownershipData processor onlyData controller - owns all employee data
Data retention and classificationEnforces per contract termsDefines policy and retention periods
Compliance reportingProvides SOC 2 report, pen test summary, DPAReviews and signs DPA
Incident notificationNotifies dfcu Bank per agreed SLAInternal escalation and regulatory reporting
Technical Contact

Questions from your IT or security team?

Brett Mulder
Managing Partner - Initial Enquiries

For initial questions, reach out to Brett who will connect you with the appropriate technical resource.

Rob Heymann
Technical Lead - Due Diligence & Integration

For security questionnaires, SOC 2 report requests, DPA, and IT integration planning. Full security documentation pack available under NDA.