//AIRGAPT turns the FIDO2 security key your employees already use into a hardware anchor that enforces working-time boundaries and generates tamper-evident, court-auditable proof, composable with the payroll, WFM, HRIS, time-attendance, and wellbeing tools you already run.
The enforcement driver enforces the working-time boundary using locally-cached, cryptographically signed policy. Enforcement decisions happen at the device, no cloud round-trip in the enforcement path. Offline endpoints enforce correctly.
Every event, enforcement, voluntary override, reconnection, is signed by the employee's non-exportable FIDO2 private key and written to a tamper-evident, hash-chained log evidence database. Neither the employer nor any system administrator can alter an existing entry.
Signed events sync to the cloud control plane on a heartbeat. The ledger exports in court-ready, chain-of-custody format, compatible with standard eDiscovery and labour-authority audit tooling.
// Architecture note: enforcement decisions happen at the device layer via the enforcement driver on locally-cached signed policy. Cloud control plane distributes policy in advance; it is not in the critical path of any enforcement decision. Offline endpoints continue to enforce correctly.
Honest scope: Enforces on computers (PC) today. Mobile and frontline/field capture are on the roadmap.
When a labour inspector or plaintiff's counsel demands your working-time records, the employer's defence rests on a single question: can these records be altered after the fact?
Spreadsheets can. HRIS exports can. Most time-tracking tools can. //AIRGAPT cannot. Every record is signed by the employee's own non-exportable hardware key. The employer has no write access to submitted entries. The chain is tamper-evident.
The tamper-evident //AIRGAPT log evidence database is the record of enforcement. An inspector cannot find a gap the employer could have filled in after the fact.
A hardware-signed chain of events vs. HR system testimony. Spanish courts and the CJEU (C-55/18) have been explicit on which carries more weight.
The log evidence database proves actual hours worked, not contracted hours. It defends the pay calculation from underpayment claims and from overclaiming.
//AIRGAPT records a signed work-state event: the fact that a hardware key was engaged or disengaged, timestamped, with pseudonymous device identity. It does not record what was typed. It does not record where the employee was. It does not record biometric data. It does not record communication content or metadata.
This is architectural, not a limitation. Special-category biometric data under GDPR Art.9 requires explicit consent, a documented legitimate processing basis, and DPA registration in most EU member states. Biometric clocks carry this burden. GPS-based attendance systems carry a location-data burden. //AIRGAPT avoids both. The physical act of engaging a FIDO2 key produces a signed event. The key is not a body. The event is not biometric data.
Works council angle: This design matters significantly for German co-determination (Betriebsrat), Dutch OR, and French CSE approval processes. Privacy-light by design removes the most common works-council objection, that the attendance system is a surveillance tool. //AIRGAPT produces no location trail, no content records, and no behavioural profile.
//AIRGAPT is a neutral evidence layer, not a system of record. It does not replace your payroll, WFM, or HRIS. It attaches hardware-anchored proof to the events those systems already track.
Feed the unspoofable source of truth that defends the pay calculation. The //AIRGAPT log evidence database provides an employer-unalterable record of actual hours, the evidence layer that makes the payroll output defensible in an underpayment dispute or labour audit.
Write signed enforcement evidence back on top of roster and boundary data. WFM tools flag violations; //AIRGAPT prevents them and returns a hardware-signed record of what happened at enforcement time, closing the gap between "the policy said" and "the log evidence database proves."
Marketplace plugin, prove the policy was enforced. HRIS platforms define the working-time policy; //AIRGAPT returns a signed attestation that the boundary was enforced at the driver level. The HRIS record gains a tamper-evident evidence layer it couldn't produce alone.
Attach tamper-evident enforcement evidence to the attendance events wellbeing and EAP tools already track. //AIRGAPT does not replace wellbeing tooling, it provides the verified boundary event that confirms rest was taken, not just logged.
//AIRGAPT activates on the FIDO2 security keys your organisation has already deployed, YubiKey, Feitian, and other FIDO Alliance-certified authenticators already in use for MFA or passwordless authentication. The BYOK commissioning model means your security team retains custody of key material throughout.
YubiKey, Feitian, FIDO Alliance-certified. No new hardware procurement.
Intune · Jamf · SCCM. No manual agent install per endpoint.
From signed agreement to first enforcement event.
//AIRGAPT is a device-level enforcement layer that makes your policy provable, not just documented. It does not replace the systems that define that policy.
We do not manage employment contracts, payroll, or HR records.
We do not plan shifts, rosters, or workforce capacity.
We do not handle communication, notifications, or collaboration.
We do not provide counselling, well-being content, or burnout therapy.
We do not interpret legislation or give legal advice.
Workforce compliance is a cross-functional responsibility. Here is how //AIRGAPT maps to each stakeholder's mandate.
Calculate your working-time liability, or contact us to discuss integration, partnership, and API access.