About CirroPeople
We build HR software for organizations that outgrew spreadsheets but do not want an enterprise implementation project to escape them.
Why we built it
Small and mid-sized organizations end up running HR across a shared drive, a spreadsheet of leave balances and a folder of scanned contracts nobody has checked for expiry. It works until someone leaves, an auditor asks a question, or a contract lapses unnoticed.
The tools meant to fix this are usually built for a single large company. They assume one organization, one set of roles and one payroll model — which makes them a poor fit for a group with several businesses, an accountancy practice serving many clients, or a technology company running a large internship programme alongside its permanent staff.
CirroPeople starts from the opposite assumption: many unrelated organizations share one platform, and keeping them apart is the hardest and most important thing the software does.
Who it is for
Organizations between roughly five and several hundred people, where one or two people carry HR alongside another job and need the system to remember things for them.
We pay particular attention to internships. Many of our customers run structured programmes with mentors, technology tracks, weekly reports and a real conversion path to permanent employment — and most HR tools treat an intern as an employee with a shorter contract, losing everything that makes the programme worth running.
CM Cloud Hosting was our first customer organization and remains the one we test most of our thinking against — but nothing in CirroPeople is specific to them. Every organization on the platform uses the same code paths, the same entitlement engine and the same separation guarantees.
How we build
Separation is a feature, not a footnote
Multi-tenancy is where HR platforms most often go wrong, and the failure is silent — nobody notices one company can see another until it matters enormously. We enforce it in the schema, in the data layer, in the database rules and in the test suite, and we treat any leak as release-blocking.
Your data stays yours
We never delete customer data because a trial lapsed or a limit was reached. When you exceed a plan you keep reading, reporting and exporting everything — you just cannot add more until you upgrade or archive. Exports are always available, in formats you can actually open.
Records should survive scrutiny
Finalized performance reviews and payroll runs become immutable. Leave is an append-only ledger rather than a number someone edits. Asset assignment history is never overwritten. When an auditor asks what happened, there is an answer.
Honest about what is configured
If no payment provider is connected, the product says so plainly rather than pretending a subscription is paid. If a business was created without payment, that is recorded with who authorised it and why.
Boring technology, carefully used
A conventional stack, applied consistently: server-side authorization, validated inputs, protected file downloads, redacted audit logs. Most security comes from doing the ordinary things everywhere, not from anything clever.
Try it with your own people data
Import a spreadsheet, invite a colleague and see whether it fits how you actually work.