Security
Last updated 8 October 2026
FastKPIs handles performance reviews, so we treat them as confidential by design. This page explains how, in plain terms.
Data hosting region
Your data is stored in Singapore: our database runs in Supabase's Singapore region and the application runs on Vercel's Singapore region. Email delivery, payments and the AI model are provided by the services listed on our subprocessors page, some of which operate outside Singapore.
Each organisation's data is kept separate
Every record belongs to an organisation and, where relevant, a department. The database itself enforces who can read or change each record (row-level security), not just the app's screens. Automated tests check on every change that one organisation can't see another's data, that a manager can't see another department's reviews, and that one employee's link can't open another's review.
Private review links
- Each review link is a long random code (256 bits), unique to one review. We store only a one-way hash of it, never the link itself.
- Links expire, can be switched off at any time, and stop working when an appraisal is completed or a cycle is closed.
- Opening a link swaps it for a private browser cookie and a clean address, so the link doesn't linger in browser history or get passed to other sites.
- Email security scanners that open links in advance can't use them up or lock the employee out.
Who can see what
Employees see only their own review. Reviewers see the reviews assigned to them; department admins and managers see their department's reviews. Reviewers' private notes are never shown to employees. FastKPIs staff don't read review content: our support tools show counts, not answers.
AI never evaluates your staff
AI only drafts KPI templates from role descriptions. Employee names, emails, answers, scores and comments are never sent to the AI model. When you import a spreadsheet, columns that look like names, emails, scores or comments are removed before anything reaches the AI.
In transit and at rest
All traffic uses HTTPS, with strict transport security. Our database provider encrypts stored data at rest. Pages use a strict content security policy so injected scripts can't run, and can't be embedded in other sites.
Payments and webhooks
Card payments are handled entirely by Stripe; we never see card numbers. A paid cycle unlocks only once Stripe confirms the payment to us directly, and every message from Stripe and our email provider is checked for a valid signature and processed only once.
Abuse protection and secrets
Sign-in codes, review links, AI requests, uploads and other public actions are rate-limited. Secret keys live only on our servers, and every release is checked automatically to make sure none of them can reach a browser.
Backups
The production database is backed up daily by our database provider.
Certifications
We don't hold certifications such as SOC 2 or ISO 27001. If your organisation needs a security questionnaire answered, email support@fastkpis.com.
Reporting a security issue
If you think you've found a security problem, please email support@fastkpis.com and we'll respond quickly.