What is built today

Everything an HR team has to run, and prove, in one place

Nine statutes, your own internal policies, and the engagement side of the job — recognition, rewards, celebrations, challenges and pulse surveys — on one platform, over one employee list, behind one privacy boundary. Each obligation becomes a control with an owner and a due date, and every figure in an export resolves back to the event that produced it. What is on this page ships today.

What it does

Your own policies, not just the statutory ones

Upload or author an internal policy, version it, and exclude the people it does not apply to. Employees acknowledge it themselves — the system will not let anyone acknowledge on another person’s behalf — and where a policy needs a second signature, attestation is recorded separately from the person being attested for.

Coverage is a number you can look at rather than a mail-merge you have to run.

Adherence that chases itself

Reminders go out ahead of the deadline, escalate when they are ignored, and come back around when a policy is due for review or reattestation. Nobody maintains a spreadsheet of who has read what.

Every one of those decisions is a plain comparison against a date. No model, no inference.

Statutory obligations as running controls

Each obligation across the nine statutes becomes a control with one owner, one due date and one status — and a new law arrives as configuration rather than a rebuild, because the engine reads the statute as data.

That has been proven once already: a second Act was added without changing the engine.

An audit pack that proves itself

The export is assembled from the evidence ledger, and it is built so an inspector can verify it without needing access to the system that produced it. Every figure resolves back to the event behind it.

Statutory exports are version-pinned, so a return filed last year regenerates as it was filed.

A privacy boundary that is data, not a promise

Who may see what, under which lawful basis, sits in a versioned and append-only matrix. It is the same source the software consults on every read, which is why the boundary is enforceable rather than described.

Changing it leaves a record. It cannot be quietly widened.

Training, with the register attached

Sessions carry their own reminder and escalation cadence, and completion writes to the register the law asks the employer to hold — at the moment it happens.

The evidence is the by-product, not a second job.

It joins your existing stack, not replaces it

Single sign-on with just-in-time provisioning, SCIM for joiners and leavers, HRIS sync, org-tree import, and a CSV roster route for the sites that are not on any of it yet. People arrive and depart through the systems you already run.

A leaver deprovisioned in your identity provider stops being a leaver you have to remember here.

And the engagement side of HR

enabled per tenant

The same platform runs recognition, rewards, celebrations, wellness challenges and pulse surveys — switched on as a pack when you want them. It is the half of HR that usually means a second vendor, a second contract and a second copy of your employee list.

Recognition and rewards

Peer recognition with a feed and reactions, a points wallet, and a reward catalogue with redemption and fulfilment.

Wellness challenges

Run a challenge, track progress, and show a leaderboard — which any participant can keep themselves off without leaving the challenge.

Celebrations

Birthdays, work anniversaries and a Secret Santa round that pairs itself. Personal dates appear only where the person has opted in.

Pulse surveys and announcements

Ask a question, read the result as a group figure, and send an announcement that records who acknowledged it.

Engagement that survives a data-protection audit

Most engagement tools broadcast a birthday because they have the date, and publish a leaderboard because they have the score. Here a personal date appears only where the person opted in, any participant can stay off a leaderboard without leaving the challenge, and pulse responses are pseudonymised and released only as a group figure above a minimum cohort — with repeat aggregate queries rate-limited, so a narrow question cannot be asked many ways until it identifies someone.

It is the same privacy machinery the statutory side runs on, because it is the same platform. That is the point of not buying this from somebody else.

One platform, not a list of vendors to chase

The usual way this gets solved is one vendor for harassment training, another for the whistleblower line, a third for surveys, a fourth for rewards, and a spreadsheet holding the parts nobody sells. Each one needs its own contract, its own security review, its own copy of your employee list, and its own person inside HR to chase it.

That overhead is not the work. It is the tax on the work. One platform means one roster, one privacy boundary, one audit trail and one renewal — and an HR team that operates the thing themselves rather than coordinating five suppliers who have never met.

Nothing here decides anything by inference

Every reminder, escalation, due date and coverage figure is a plain comparison against a date or a count. There is no model in the decision path and no artificial-intelligence feature in the product — nothing an employee writes is sent to an AI provider, because the application does not use one. For compliance evidence that is a feature rather than a limitation: a deterministic rule produces the same answer twice and can be explained to an auditor in a sentence.

How that is stated in the privacy notice →

The nine statutes it covers

Going deeper