People Group Services
CIS
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

API & Integration Security Policy

Purpose

The purpose of this policy is to establish robust security controls governing the design, development, deployment, and management of all APIs (Application Programming Interfaces) and system integrations used by People Group Services Ltd (“PGS”).

This policy ensures that all integrations:

  • Protect sensitive payroll and personal data
  • Maintain compliance with UK GDPR, Data Protection Act 2018, and HMRC requirements
  • Safeguard against unauthorised access, fraud, and data leakage
  • Support PGS’s commitment to real-time transparency and compliance without compromise

Scope

This policy applies to:

  • All internal and external APIs developed or consumed by PGS
  • Integrations with:
    • Recruitment agencies
    • MSPs and end clients
    • Payroll providers and umbrella systems
    • HMRC systems and tools
    • Third-party SaaS platforms
  • All employees, contractors, developers, and third parties involved in integration design or usage

Core Principles

PGS adopts the following principles for API and integration security:

Least Privilege Access

Access to APIs must be restricted to the minimum required permissions necessary for functionality.

Zero Trust Architecture

All API requests must be authenticated, authorised, and validated regardless of origin.

End-to-End Encryption

All data transmitted via APIs must be encrypted in transit and, where applicable, at rest.

Transparency with Control

While PGS provides granular real-time payroll transparency, access to data must be:

  • Role-based
  • Explicitly authorised
  • Fully auditable

Authentication & Authorisation Controls

Authentication Standards

All APIs must implement secure authentication mechanisms, including:

  • OAuth 2.0 or equivalent token-based authentication
  • API keys (where appropriate, with strict controls)
  • Mutual TLS (mTLS) for high-risk integrations

Multi-Factor Authentication (MFA)

Administrative access to API management systems must require MFA.

Token Security

  • Tokens must be time-limited and securely generated
  • Refresh tokens must be securely stored and rotated
  • Revocation mechanisms must be in place

Role-Based Access Control (RBAC)

Access to API endpoints must be governed by RBAC:

  • Agency-level access limited to their own workers
  • MSP-level access limited to authorised supply chain data
  • Full audit of permission assignments

Data Protection & Privacy

Data Minimisation

APIs must only expose data strictly required for the intended purpose.

Personal Data Handling

All APIs processing personal data must:

  • Comply with UK GDPR principles
  • Ensure lawful basis for processing
  • Support subject rights (access, rectification, erasure where applicable)

Sensitive Data

Special care must be taken with:

  • Payroll data (gross pay, tax, NI, employer liabilities)
  • Banking information
  • National Insurance numbers

Data Masking & Redaction

Where appropriate:

  • Data must be masked or redacted (e.g. MSP views of agency data)
  • Non-relevant supply chain data must not be disclosed

Secure API Design & Development

Secure Development Lifecycle (SDLC)

All APIs must follow secure development practices, including:

  • Code reviews
  • Static and dynamic security testing
  • Dependency vulnerability scanning

Input Validation

All API inputs must be validated to prevent:

  • Injection attacks (SQL, command, etc.)
  • Malformed requests
  • Data corruption

Output Handling

APIs must:

  • Prevent data leakage through error messages
  • Avoid exposing internal system details

Version Control

  • APIs must be versioned (e.g. /v1/, /v2/)
  • Deprecated versions must be securely retired

Encryption & Transmission Security

Transport Layer Security

All API communications must use:

  • TLS 1.2 or higher
  • Strong cipher suites

Certificate Management

  • Certificates must be valid and regularly renewed
  • Automated monitoring for expiry

Data Integrity

Mechanisms must ensure data has not been tampered with in transit.

Logging, Monitoring & Audit

Audit Logging

All API activity must be logged, including:

  • Authentication attempts
  • Data access events
  • Permission changes
  • Errors and anomalies

Real-Time Monitoring

Systems must monitor for:

  • Unusual access patterns
  • High request volumes (potential abuse)
  • Failed authentication attempts

Audit Trail Retention

Logs must be retained in accordance with:

  • Legal and regulatory requirements
  • PGS Data Retention Policy

Rate Limiting & Abuse Prevention

To protect systems and data:

  • API rate limits must be enforced
  • Throttling applied to excessive requests
  • Protection against:
    • DDoS attacks
    • Credential stuffing
    • Automated scraping

Third-Party Integrations

Due Diligence

All third-party integrations must undergo:

  • Security assessment
  • Data protection review
  • Contractual safeguards

Data Sharing Agreements

Formal agreements must define:

  • Data usage
  • Security obligations
  • Liability and breach responsibilities

Continuous Monitoring

Third-party integrations must be periodically reviewed for:

  • Security posture
  • Compliance adherence

HMRC & Payroll Integration Controls

Given PGS’s integration with HMRC-aligned systems:

  • API outputs must reflect accurate PAYE, NI, and RTI data
  • Real-time checks must not compromise system security
  • Access to HMRC-related data must be:
    • Logged
    • Controlled
    • Restricted to authorised users

Incident Management

API Security Incidents

Any suspected API breach or vulnerability must be:

  • Reported immediately
  • Investigated in line with the Data Incident Response Policy

Containment Measures

PGS may:

  • Revoke API keys/tokens
  • Disable endpoints
  • Restrict integration access

Notification

Where required:

  • ICO and affected parties will be notified in accordance with UK GDPR

Business Continuity & Resilience

  • APIs must be designed for high availability and failover
  • Backup systems must ensure continuity of service
  • Critical integrations must have redundancy measures

Responsibilities

IT & Development Teams

  • Implement secure API design
  • Maintain documentation
  • Monitor and respond to threats

Compliance & Data Protection

  • Ensure GDPR compliance
  • Review data sharing practices

Third Parties

  • Must adhere to PGS security standards
  • Subject to audit and contractual obligations

Training & Awareness

All relevant personnel must receive:

  • Secure development training
  • API security awareness
  • Data protection training

Policy Compliance & Review

Failure to comply with this policy may result in:

  • Disciplinary action
  • Termination of contracts
  • Legal consequences

This policy will be reviewed:

  • Annually
  • Following significant system or regulatory changes

Alignment with Standards

This policy aligns with:

  • UK GDPR & Data Protection Act 2018
  • Cyber Essentials Plus
  • ISO 27001 (best practice principles)
  • HMRC digital reporting requirements

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 25th March 2026