Security & compliance

Where your biometric attendance data lives, and who can touch it

Biometric attendance earns suspicion by default — employees hear "fingerprint database" and imagine images of their fingers in a spreadsheet. The suspicion deserves a precise answer, not a trust-us page. This is that answer: what is collected, what is mathematically impossible with it, where it is stored, and which certifications stand behind the company holding it.

A properly built biometric attendance system never stores fingerprint or face images. The terminal computes a mathematical template — a set of numbers describing features — and matching compares numbers to numbers; the original image is not retained and cannot be reconstructed from the template. In AionHRMS, templates exist for exactly one purpose (synchronising enrolment across your terminals), are never displayed in any interface, are excluded from ordinary exports and from the API entirely, and are deleted when the employee is deleted. Attendance data is stored on infrastructure in India, access is scoped by role, and the platform is built by AIONDATA — ISO 9001:2015 certified and CMMI Level 3 appraised, with SOC 2 Type II, GDPR and HIPAA readiness. Under India's DPDP framework you remain the data fiduciary for your employees' data; we process it on your instruction, and for nothing else.

Templates

mathematical features — never images, never reconstructable

In India

attendance data stored on Indian infrastructure

No Aadhaar

no Aadhaar data is collected or touched, ever

Scoped

role-based access for people, hashed scoped keys for software

What is actually collected — and what is not

The honest inventory is short. For each employee: their profile as you enter it, the biometric templates captured at enrolment, and their punches — timestamp, terminal, verification method. That is the entire biometric footprint.

  • Templates, not images: the terminal derives numerical features; no photograph of a fingerprint or face is retained
  • A template cannot be reversed into the fingerprint or face it describes
  • No Aadhaar numbers, no government-database linkage of any kind — see our AEBAS explainer for why that matters
  • Punches record facts about presence, not location tracking: a person, a terminal, a moment, a method

Where templates live and who can see them: nobody

Templates are the sensitive asset, so their handling is the strictest rule in the product — they are functional data for device synchronisation, not information anyone reads.

  • Stored centrally so a replaced terminal can be re-populated without re-enrolling staff
  • Never rendered in any screen of the product — there is nothing to shoulder-surf
  • Never included in attendance exports; no API scope exposes them
  • Deleted when the employee is deleted; retained through a block/unblock so access can resume without re-enrolment

Access control on the data itself

The register is only as private as the weakest login that can read it, so access is scoped at every layer — human and machine.

  • Role-based access: a branch administrator sees their branch; payroll figures require the payroll permission
  • Transport encrypted; sessions authenticated per user, not shared logins
  • API access via scoped keys — read and write separated, shown once, stored only as a SHA-256 hash
  • Per-key rate limits, quotas and a full request log, revocable instantly
  • Within our team, production access is limited to the people who operate and support the service

The company behind the data

Security claims are only as good as the organisation making them, so here are AIONDATA's credentials with their exact qualifiers — the wording matters, and we keep it precise.

  • ISO 9001:2015 — certified quality management system
  • CMMI Level 3 — appraised: a defined, documented engineering process
  • SOC 2 Type II — ready: controls prepared; stated as readiness, not an issued attestation
  • GDPR and HIPAA — ready, same precise sense
  • Engineering in Noida, headquarters in California; the people who build the system support it

Your obligations, our role — plainly

Indian employers may collect biometric attendance, and many establishments are required to keep attendance registers. Collecting it responsibly is a shared arrangement, and the division of duties should be written down, not assumed.

  • Under India's DPDP framework, you remain the data fiduciary for your employees' data; we process it on your instruction
  • Tell staff what is collected, why, and how it is protected — this page exists partly so you can show them
  • Use the data for attendance, access and payroll — the purposes stated — and nothing else; we do the same
  • Attendance is exportable while your account is active and on request when ending a subscription — ask any vendor for that in writing
  • We do not sell, share or mine your data; there is no advertising business attached to your register

Questions to put to any attendance vendor — with our answers

QuestionAionHRMSCommon answer elsewhere
Are fingerprint images stored?No — templates only, on the terminal and centrally.Often unknown to the person selling it.
Who can view biometric data?Nobody — it is never displayed or exported.Whoever uses the desktop software's PC.
Where is the data stored?Infrastructure in India.An office PC, or a cloud with no stated residency.
What happens on employee exit?Deleting the employee deletes their templates.Templates linger on devices indefinitely.
Company certifications?ISO 9001:2015 certified; CMMI L3 appraised; SOC 2 / GDPR / HIPAA ready.Rarely published for attendance software.
Can we take our data out?Yes — exportable, and stated in writing.Ask, and get it in writing before you sign.

Frequently asked questions

Is biometric attendance safe for employees?
Done properly, yes — and "properly" is checkable. The system should store mathematical templates rather than images, never display or export them, delete them with the employee, and hold data with a stated location and stated access rules. AionHRMS does all of these, and this page is written so you can show it to staff who ask.
Can a fingerprint be recreated from the stored template?
No. The template is a one-way derivation — numbers describing features, sufficient to compare a live scan against, insufficient to reconstruct the fingerprint or face that produced it. The original image is not retained after enrolment.
Is employee consent required for biometric attendance in India?
Employers should inform staff clearly about what is collected, the purpose, and how it is protected — and India's DPDP framework formalises duties around personal data, with employers as the data fiduciary. Practically: notify staff in writing, use the data only for the stated purposes, and choose a system whose data handling you can actually describe. We provide the description; the notification is yours.
Is attendance data shared with anyone?
No. Your data is processed to run the service for you — attendance, access and payroll — and for nothing else. It is not sold, not shared across customers, and not mined for any other business. Within our team, production access is limited to the people who operate and support the service.
Is AionHRMS SOC 2 certified?
Precisely: AIONDATA is SOC 2 Type II ready — controls prepared, stated as readiness rather than an issued attestation — alongside GDPR and HIPAA readiness, ISO 9001:2015 certification and a CMMI Level 3 appraisal. We keep those qualifiers exact because a security page that inflates its own certifications has told you everything about its other claims.

Security you can explain to your own employees

Templates not images, data in India, access that is scoped and logged. Ask us anything this page did not answer.