Trust

Security and data protection

Updated September 27, 2026

How Bomuno protects access

Bomuno requires authenticated access to workforce records. Protected actions check the signed-in person's company membership, role, and permissions. Company data is scoped to its workspace so one customer is not meant to read or change another customer's employee records. Sensitive operations are recorded where the product provides an audit history.

Mobile screen-capture protection

Production iOS and Android apps request operating-system protection against screenshots and screen recording across the whole Bomuno window, including employee records, payslips, messages, images, and attachments. Sensitive content is also hidden from supported app-switcher previews.

This safeguard is intentionally broad, but it is not absolute. Another camera, a modified or compromised device, an operating-system defect, or an unsupported device may still copy what is visible. Users must continue to treat workforce information as confidential.

Desktop and browser limitation

A website cannot reliably stop a computer's operating system, browser tools, screen-recording software, or another camera from capturing the screen. Bomuno does not claim otherwise. The web application relies on sign-in, company separation, authorization, session security, and responsible use. Companies should grant the least access each person needs and remove access promptly when it is no longer required.

Device permissions and data minimization

Bomuno version 1 does not request background location. Precise location is requested only during a deliberate clock-in or clock-out when the company uses work-site verification. Camera, photo, microphone, files, and notifications are requested only for the features that use them. Bomuno does not request photo-library permission merely to detect screenshots.

Operations and support access

Bomuno uses managed providers for parts of hosting, authentication, email, push delivery, and diagnostics. Access to production systems and customer data should be limited to authorized people who need it for operations, requested support, incident response, safety, or legal obligations. Support messages go to the Bomuno support queue and may generate an email alert to the team.

Report a security concern

Do not include passwords, active sign-in codes, private keys, or unnecessary employee data in a report. Use signed-in Bomuno support when possible or email security@bomuno.com. Include what happened, when it happened, the affected screen or account, and a safe way to contact you. We will acknowledge the report and prioritize issues according to risk.

Scope of this statement

This page describes current product practices and limits; it does not claim a security certification or guarantee that incidents cannot happen. See the Privacy Policy for data handling and the Terms of Service for customer and user responsibilities.

Security · Bomuno