Please access this document via the main proposal.
Prepared for dfcu Bank IT and security teams. This document covers cloud architecture, encryption, authentication, data governance, AI processing, and compliance certifications. Full SOC 2 Type 2 report, penetration test summary, and DPA are available under NDA.
The Peopletree platform runs entirely on Microsoft Azure. dfcu Bank's data is hosted in the EU, isolated from all other clients, and managed end-to-end by Peopletree - with zero infrastructure overhead for your IT team.
All platform components run on Azure Germany West Central, within a private virtual network. No public-facing management ports are exposed.
dfcu Bank operates in a logically isolated tenant environment. Your data is never commingled with other clients and access is strictly controlled at the tenant boundary.
The platform uses Auth0 for identity management, supporting SAML 2.0 and Microsoft Entra ID federation. dfcu Bank can integrate its existing identity provider with no additional tooling.
All data is encrypted at rest and in transit using FIPS 140-2 compliant standards. Production access is restricted to authorised Peopletree engineers, logged, and auditable.
TAILA uses Azure OpenAI Service, hosted in the EU. All AI processing is stateless - no employee data is retained by the AI model, stored in training datasets, or used to improve the underlying model. Prompts contain only structured talent data; no personal or identifiable information is included.
Each AI interaction is processed independently. No conversation history, employee profiles, or assessment data is retained between sessions.
dfcu Bank data is never used to train or fine-tune the underlying model. Microsoft's enterprise data protection commitments apply in full.
All AI processing occurs within Azure Germany West Central. Data does not cross the EU boundary during AI processing.
The platform integrates with any data source via REST API, SFTP, or direct database connection. dfcu Bank retains full ownership and control of all employee data throughout.
Peopletree builds and maintains the integration. dfcu Bank provides data access and an IT liaison contact. No ongoing maintenance is required from your team.
Transfer methods: REST API (HTTPS / TLS 1.2), Secure SFTP (TLS 1.2, key-pair auth), Azure ETL pipeline, or direct database integration on request.
| Parameter | Detail |
|---|---|
| Data ownership | dfcu Bank is data controller; Peopletree is data processor only |
| Tenant isolation | Logical isolation per client; dedicated database schemas; no cross-tenant access |
| Data classification | Formal policy - confidential, internal, and public tiers |
| Data retention | Defined per contract; data purged on request within agreed SLA |
| Data residency | EU-based Azure data centre (Germany West Central); CDN edge nodes for static assets only |
| Backup | Azure-managed geo-redundant; point-in-time restore available |
| GDPR / POPIA | Data Processing Agreement available; customer controls classification and retention |
| Uganda DPA 2019 | Platform architecture satisfies Uganda Data Protection and Privacy Act 2019 requirements - EU-compliant data residency, processor obligations, and consent management apply |
| Area | Detail |
|---|---|
| Change management | All changes reviewed, tested, and approved before deployment; continuous vulnerability scanning; critical patches within 24 hours |
| Incident response | Documented plan covering identification, containment, remediation, and communication; affected parties notified within agreed windows |
| Log retention | 90-day+ via Azure Monitor and Log Analytics Workspace |
| Business continuity | Documented BC/DR plan; geo-redundant storage with point-in-time restore; redundant infrastructure with Azure load balancing |
| Personnel security | Security awareness training and background checks for all staff; access revoked within 24 hours of termination |
| Vendor security | All vendors assessed for security compliance before onboarding |
Full reports are available to dfcu Bank's IT and procurement teams under NDA. Contact Rob Heymann to initiate.
| Area | Peopletree Group | dfcu Bank |
|---|---|---|
| Platform hosting and infrastructure | Fully managed | No action required |
| Security patching and updates | Fully managed | No action required |
| WAF and network security | Fully managed (Azure WAF v2) | No action required |
| Backup and recovery | Automated geo-redundant backups | No action required |
| User access provisioning | Managed via admin portal | HR admin approves user requests |
| SSO / identity integration | Configures SAML / Auth0 connection | Provides IdP metadata and IT liaison |
| HRIS / payroll data integration | Builds and maintains integration | Provides data access and IT liaison |
| Data ownership | Data processor only | Data controller - owns all employee data |
| Data retention and classification | Enforces per contract terms | Defines policy and retention periods |
| Compliance reporting | Provides SOC 2 report, pen test summary, DPA | Reviews and signs DPA |
| Incident notification | Notifies dfcu Bank per agreed SLA | Internal escalation and regulatory reporting |
For initial questions, reach out to Brett who will connect you with the appropriate technical resource.
For security questionnaires, SOC 2 report requests, DPA, and IT integration planning. Full security documentation pack available under NDA.