Security is built into the structure

In Kelomo everyone sees only the data their role entitles them to. Changes leave an auditable trace, integration credentials stay encrypted, and the servers and data stay in Finland.

Structural security

Roles and visibility

The employee, supervisor, payroll and admin each see different things. No one sees more than their role requires.

Auditable change history

Confirmed data is never edited in place. Every correction is recorded as its own event, and the original data is preserved.

Encrypted integration credentials

Payroll and integration credentials are encrypted and never shown in the interface.

Data in Finland

The production environment and the data are in Finland – where the system is also designed, built and maintained.

Single sign-on (SSO)

Sign in with your organisation’s own accounts: Microsoft Entra ID, Google Workspace or another OIDC-compatible identity provider.

Data moves in and out

An open REST API, webhooks (including Slack and Teams), calendar feeds, and CSV import and export.

To support procurement

Encryption, isolation and backups

All traffic is TLS-encrypted, and the database and its backups are encrypted at rest as well. Each customer’s data is isolated at the database level, and the boundary applies to every query.

The database is backed up automatically and can be restored to a point in time when needed. The production environment is in Finland: the database and the applications in Hetzner’s Helsinki data centre.

Incidents and service level

In the event of a security incident we notify the customer without undue delay, in line with the GDPR and the data processing agreement. The service level description (SLA) is accepted at onboarding and is available to read during procurement itself.

Data lifecycle and data subject rights

The lifecycle of personal data is managed to the end: after an employment ends, the data is anonymised in stages by data class, and every stage requires an admin’s sign-off. The statutory working-time records are kept for the retention period even though the person’s identifying details are removed.

A data subject’s access request is answered with a machine-readable export and a PDF summary, and the admin can browse the change history as an audit log in settings. Optional AI features, such as receipt text recognition, are off by default and enabled by a deliberate choice.

Materials on processing and sub-processors

We provide a data processing agreement (DPA), an up-to-date sub-processor list and a description of roles and access rights. Ask for the materials and we’ll send them.

Book a demo or request the procurement materials.

Opening in September 2026 · 30 days free from launch, no card required

Waitlist