Workforce Tech Stack · How It Works

Enforce at the device.
Prove with cryptography.

//AIRGAPT turns the FIDO2 security key your employees already use into a hardware anchor that enforces working-time boundaries and generates tamper-evident, court-auditable proof, composable with the payroll, WFM, HRIS, time-attendance, and wellbeing tools you already run.

The Architecture

Three layers. One source of truth.

Local Enforcement

The enforcement driver enforces the working-time boundary using locally-cached, cryptographically signed policy. Enforcement decisions happen at the device, no cloud round-trip in the enforcement path. Offline endpoints enforce correctly.

Cryptographic Evidence

Every event, enforcement, voluntary override, reconnection, is signed by the employee's non-exportable FIDO2 private key and written to a tamper-evident, hash-chained log evidence database. Neither the employer nor any system administrator can alter an existing entry.

Sync & Export

Signed events sync to the cloud control plane on a heartbeat. The ledger exports in court-ready, chain-of-custody format, compatible with standard eDiscovery and labour-authority audit tooling.

Enforcement Log
Pre-cached policy → Enforcement driver → Tamper-evident log evidence database
18:00:00The enforcement driver enforces the boundary per pre-cached signed policy. No cloud round-trip in the enforcement path. The working-time boundary is enforced at the device.
18:00:01Cryptographic enforcement event signed locally and written to the tamper-evident log evidence database. Audit trail begins for the enforcement window.
20:14Employee chooses to work. FIDO2 hardware token re-engaged. Local driver verifies hardware authorisation, opens scoped override session.
20:47Token removed. The enforcement driver re-enforces the boundary. Override session closed. Signed override record written to log evidence database: timestamp, duration, authorising device identity.
07:59Manager attempts to send message outside recipient's window. Delivery physically blocked at the recipient endpoint, still in enforcement window per cached policy.
08:00Enforcement window lifted per cached policy. Connectivity restored. No violation logged.

// Architecture note: enforcement decisions happen at the device layer via the enforcement driver on locally-cached signed policy. Cloud control plane distributes policy in advance; it is not in the critical path of any enforcement decision. Offline endpoints continue to enforce correctly.

Honest scope: Enforces on computers (PC) today. Mobile and frontline/field capture are on the roadmap.

Evidence

Evidence that survives an inspection, and a courtroom.

When a labour inspector or plaintiff's counsel demands your working-time records, the employer's defence rests on a single question: can these records be altered after the fact?

Spreadsheets can. HRIS exports can. Most time-tracking tools can. //AIRGAPT cannot. Every record is signed by the employee's own non-exportable hardware key. The employer has no write access to submitted entries. The chain is tamper-evident.

01
Labour-inspector audit

The tamper-evident //AIRGAPT log evidence database is the record of enforcement. An inspector cannot find a gap the employer could have filled in after the fact.

02
Overtime and wage litigation

A hardware-signed chain of events vs. HR system testimony. Spanish courts and the CJEU (C-55/18) have been explicit on which carries more weight.

03
Wage-creep exposure

The log evidence database proves actual hours worked, not contracted hours. It defends the pay calculation from underpayment claims and from overclaiming.

Privacy

A key, not a body.

//AIRGAPT records a signed work-state event: the fact that a hardware key was engaged or disengaged, timestamped, with pseudonymous device identity. It does not record what was typed. It does not record where the employee was. It does not record biometric data. It does not record communication content or metadata.

This is architectural, not a limitation. Special-category biometric data under GDPR Art.9 requires explicit consent, a documented legitimate processing basis, and DPA registration in most EU member states. Biometric clocks carry this burden. GPS-based attendance systems carry a location-data burden. //AIRGAPT avoids both. The physical act of engaging a FIDO2 key produces a signed event. The key is not a body. The event is not biometric data.

Works council angle: This design matters significantly for German co-determination (Betriebsrat), Dutch OR, and French CSE approval processes. Privacy-light by design removes the most common works-council objection, that the attendance system is a surveillance tool. //AIRGAPT produces no location trail, no content records, and no behavioural profile.

Biometric clock
GPS / geofencing
AIRGAPT
GDPR data category
Special-category (Art.9)
Continuous location
Signed event metadata
Explicit consent required
Yes
Yes
No, pseudonymous hardware event
Content recorded
Biometric template
Location history
None
Evidential value
Alterable after capture
Spoofable
Hardware-signed, non-repudiable
Works-council friction
High
High
Low
Composability

Composable with the systems you already run.

//AIRGAPT is a neutral evidence layer, not a system of record. It does not replace your payroll, WFM, or HRIS. It attaches hardware-anchored proof to the events those systems already track.

Payroll / HCM
SD Worx · ADP · Visma · Sage · Dayforce · PayFit

Feed the unspoofable source of truth that defends the pay calculation. The //AIRGAPT log evidence database provides an employer-unalterable record of actual hours, the evidence layer that makes the payroll output defensible in an underpayment dispute or labour audit.

WFM / Time & Attendance
UKG · ATOSS · Quinyx · Protime · Deputy · Tanda

Write signed enforcement evidence back on top of roster and boundary data. WFM tools flag violations; //AIRGAPT prevents them and returns a hardware-signed record of what happened at enforcement time, closing the gap between "the policy said" and "the log evidence database proves."

HRIS
Personio · Factorial · HiBob · Sloneek · Lucca · Employment Hero

Marketplace plugin, prove the policy was enforced. HRIS platforms define the working-time policy; //AIRGAPT returns a signed attestation that the boundary was enforced at the driver level. The HRIS record gains a tamper-evident evidence layer it couldn't produce alone.

Time-Attendance & Wellbeing
Category: punch-clock replacement, wellbeing platforms, EAP integrations

Attach tamper-evident enforcement evidence to the attendance events wellbeing and EAP tools already track. //AIRGAPT does not replace wellbeing tooling, it provides the verified boundary event that confirms rest was taken, not just logged.

Deployment

No new hardware. No separate enrolment. 30 days.

//AIRGAPT activates on the FIDO2 security keys your organisation has already deployed, YubiKey, Feitian, and other FIDO Alliance-certified authenticators already in use for MFA or passwordless authentication. The BYOK commissioning model means your security team retains custody of key material throughout.

Activates on existing keys

YubiKey, Feitian, FIDO Alliance-certified. No new hardware procurement.

MDM-deployed

Intune · Jamf · SCCM. No manual agent install per endpoint.

30-day onboarding

From signed agreement to first enforcement event.

Scope Clarity

Where //AIRGAPT does not replace existing tools.

//AIRGAPT is a device-level enforcement layer that makes your policy provable, not just documented. It does not replace the systems that define that policy.

Not an HRIS

We do not manage employment contracts, payroll, or HR records.

Not a scheduling tool

We do not plan shifts, rosters, or workforce capacity.

Not a messaging platform

We do not handle communication, notifications, or collaboration.

Not an EAP

We do not provide counselling, well-being content, or burnout therapy.

Not a compliance auditor

We do not interpret legislation or give legal advice.

Roles & Responsibilities

Who owns what.

Workforce compliance is a cross-functional responsibility. Here is how //AIRGAPT maps to each stakeholder's mandate.

Stakeholder
Mandate
Their Tool
AIRGAPT Role
HR Director
Negotiate RTD policy, define rest windows, document obligations
HRIS / Policy Documents
Receives signed roster. Enforces the working-time boundary. Returns audit receipt.
Legal / Compliance
Ensure regulatory obligations met, avoid fines
GRC platform / Legal counsel
Produces jurisdiction-specific audit artifacts for ACT, WRC, FWC.
IT / CISO
Deploy and maintain technical enforcement layer
MDM / Group Policy
Enforcement driver deployed via MDM. Existing FIDO2 tokens provisioned. No new hardware.
People Manager
Manage team within legal rest boundaries
Slack / Teams / Email
Emergency override with FIDO2 auth. All overrides logged to audit-grade ledger.
CFO
Avoid fine liability
Financial reporting / Risk register
Provides tamper-evident enforcement evidence that defends against fine liability.
Ready to go further?

See your exposure, or explore a partnership.

Calculate your working-time liability, or contact us to discuss integration, partnership, and API access.

Back to Workforce Module
Vanguard Pilot · Now Accepting Applications
Pilot Company Waitlist Open, Setup Fees Waived for Founding Cohort