![]() |
People Group Services Limited Company Number: 11570329 |
API & Integration Security Policy
Purpose
The purpose of this policy is to establish robust security controls governing the design, development, deployment, and management of all APIs (Application Programming Interfaces) and system integrations used by People Group Services Ltd (“PGS”).
This policy ensures that all integrations:
- Protect sensitive payroll and personal data
- Maintain compliance with UK GDPR, Data Protection Act 2018, and HMRC requirements
- Safeguard against unauthorised access, fraud, and data leakage
- Support PGS’s commitment to real-time transparency and compliance without compromise
Scope
This policy applies to:
- All internal and external APIs developed or consumed by PGS
- Integrations with:
- Recruitment agencies
- MSPs and end clients
- Payroll providers and umbrella systems
- HMRC systems and tools
- Third-party SaaS platforms
- All employees, contractors, developers, and third parties involved in integration design or usage
Core Principles
PGS adopts the following principles for API and integration security:
Least Privilege Access
Access to APIs must be restricted to the minimum required permissions necessary for functionality.
Zero Trust Architecture
All API requests must be authenticated, authorised, and validated regardless of origin.
End-to-End Encryption
All data transmitted via APIs must be encrypted in transit and, where applicable, at rest.
Transparency with Control
While PGS provides granular real-time payroll transparency, access to data must be:
- Role-based
- Explicitly authorised
- Fully auditable
Authentication & Authorisation Controls
Authentication Standards
All APIs must implement secure authentication mechanisms, including:
- OAuth 2.0 or equivalent token-based authentication
- API keys (where appropriate, with strict controls)
- Mutual TLS (mTLS) for high-risk integrations
Multi-Factor Authentication (MFA)
Administrative access to API management systems must require MFA.
Token Security
- Tokens must be time-limited and securely generated
- Refresh tokens must be securely stored and rotated
- Revocation mechanisms must be in place
Role-Based Access Control (RBAC)
Access to API endpoints must be governed by RBAC:
- Agency-level access limited to their own workers
- MSP-level access limited to authorised supply chain data
- Full audit of permission assignments
Data Protection & Privacy
Data Minimisation
APIs must only expose data strictly required for the intended purpose.
Personal Data Handling
All APIs processing personal data must:
- Comply with UK GDPR principles
- Ensure lawful basis for processing
- Support subject rights (access, rectification, erasure where applicable)
Sensitive Data
Special care must be taken with:
- Payroll data (gross pay, tax, NI, employer liabilities)
- Banking information
- National Insurance numbers
Data Masking & Redaction
Where appropriate:
- Data must be masked or redacted (e.g. MSP views of agency data)
- Non-relevant supply chain data must not be disclosed
Secure API Design & Development
Secure Development Lifecycle (SDLC)
All APIs must follow secure development practices, including:
- Code reviews
- Static and dynamic security testing
- Dependency vulnerability scanning
Input Validation
All API inputs must be validated to prevent:
- Injection attacks (SQL, command, etc.)
- Malformed requests
- Data corruption
Output Handling
APIs must:
- Prevent data leakage through error messages
- Avoid exposing internal system details
Version Control
- APIs must be versioned (e.g. /v1/, /v2/)
- Deprecated versions must be securely retired
Encryption & Transmission Security
Transport Layer Security
All API communications must use:
- TLS 1.2 or higher
- Strong cipher suites
Certificate Management
- Certificates must be valid and regularly renewed
- Automated monitoring for expiry
Data Integrity
Mechanisms must ensure data has not been tampered with in transit.
Logging, Monitoring & Audit
Audit Logging
All API activity must be logged, including:
- Authentication attempts
- Data access events
- Permission changes
- Errors and anomalies
Real-Time Monitoring
Systems must monitor for:
- Unusual access patterns
- High request volumes (potential abuse)
- Failed authentication attempts
Audit Trail Retention
Logs must be retained in accordance with:
- Legal and regulatory requirements
- PGS Data Retention Policy
Rate Limiting & Abuse Prevention
To protect systems and data:
- API rate limits must be enforced
- Throttling applied to excessive requests
- Protection against:
- DDoS attacks
- Credential stuffing
- Automated scraping
Third-Party Integrations
Due Diligence
All third-party integrations must undergo:
- Security assessment
- Data protection review
- Contractual safeguards
Data Sharing Agreements
Formal agreements must define:
- Data usage
- Security obligations
- Liability and breach responsibilities
Continuous Monitoring
Third-party integrations must be periodically reviewed for:
- Security posture
- Compliance adherence
HMRC & Payroll Integration Controls
Given PGS’s integration with HMRC-aligned systems:
- API outputs must reflect accurate PAYE, NI, and RTI data
- Real-time checks must not compromise system security
- Access to HMRC-related data must be:
- Logged
- Controlled
- Restricted to authorised users
Incident Management
API Security Incidents
Any suspected API breach or vulnerability must be:
- Reported immediately
- Investigated in line with the Data Incident Response Policy
Containment Measures
PGS may:
- Revoke API keys/tokens
- Disable endpoints
- Restrict integration access
Notification
Where required:
- ICO and affected parties will be notified in accordance with UK GDPR
Business Continuity & Resilience
- APIs must be designed for high availability and failover
- Backup systems must ensure continuity of service
- Critical integrations must have redundancy measures
Responsibilities
IT & Development Teams
- Implement secure API design
- Maintain documentation
- Monitor and respond to threats
Compliance & Data Protection
- Ensure GDPR compliance
- Review data sharing practices
Third Parties
- Must adhere to PGS security standards
- Subject to audit and contractual obligations
Training & Awareness
All relevant personnel must receive:
- Secure development training
- API security awareness
- Data protection training
Policy Compliance & Review
Failure to comply with this policy may result in:
- Disciplinary action
- Termination of contracts
- Legal consequences
This policy will be reviewed:
- Annually
- Following significant system or regulatory changes
Alignment with Standards
This policy aligns with:
- UK GDPR & Data Protection Act 2018
- Cyber Essentials Plus
- ISO 27001 (best practice principles)
- HMRC digital reporting requirements
Declaration
This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329
Last updated: 25th March 2026

