Security, reliability, and responsible AI - all in one place.
Breathe is ISO 27001 and ISO 42001 accredited, so you can have peace of mind that your data is safe and secure
Breathe is ISO 27001 and ISO 42001 accredited, so you can have peace of mind that your data is safe and secure
At Breathe, the trust you place in us is something we take seriously every single day. Your data is protected by enterprise-grade security, your service runs on resilient UK-based infrastructure, and now our commitment goes even further - with ISO 42001, making Breathe one of the few UK companies to hold this certification.
Breathe is proud to have been awarded ISO 42001 accreditation, the international standard for AI management. This sits alongside our ISO 27001 compliance certification and the accreditations of our hosting provider, Amazon Web Services.
As a Breathe customer, you'll trust us to look after your employee data – a responsibility we take incredibly seriously.
This page explains the steps we take to protect your data, as well as how we ensure you have access to your data whenever and wherever you need it.
100% of Breathe users agree - Breathe’s security and data protection standards give us confidence in handling sensitive employee information.
- Breathe HR 2025 customer survey.
ISO/IEC 42001:2023 is the world's first international standard dedicated to Artificial Intelligence Management Systems (AIMS). Published by the International Organization for Standardization (ISO), it provides a structured framework for how organisations develop, deploy, and govern AI responsibly - addressing everything from ethical considerations and transparency to risk management and ongoing accountability.
Unlike general data or security standards, ISO 42001 is built specifically for the age of AI. It helps organisations prove, not just promise that their use of AI is fair, safe, and well-managed.
AI is being embedded into software products at pace, and with that comes real responsibility. ISO 42001 accreditation matters for tech companies for three core reasons:
Trust: It signals to customers, regulators, and partners that AI is being used responsibly, backed by independent, third-party validation, not just internal policy documents.
Risk reduction: The standard requires organisations to identify, assess, and control AI-related risks throughout the full lifecycle of any AI system — from design to deployment.
Future-readiness: With frameworks like the EU AI Act shaping global regulation, ISO 42001 positions certified companies ahead of the curve rather than scrambling to comply after the fact.
For businesses choosing HR software, it means you can trust that any AI-powered features in Breathe - whether those are analytics, automation, or intelligent workflows - are governed by a certified, independently audited standard.
We're delighted to have been awarded ISO 42001 accreditation, making Breathe one of a small number of HR software providers to hold this certification. This builds directly on our existing ISO 27001 information security certification, reinforcing our commitment to keeping your people's data safe, your systems reliable, and our use of technology ethical and transparent.
Breathe is ISO 42001 and ISO 27001 certified - independently audited and rigorously maintained.
Breathe is the trading name of Centurion Management Systems Ltd, a UK-based company that has been designing and implementing HR systems for over 21 years.
We know how important it is for you to have access to your HR systems whenever and wherever you need them. That’s why our servers are configured to provide an exceptionally high level of reliability.
Visit status.breathehr.com to see the live status of our servers at any time.
We don't hold or process any credit card information on our servers.
From the very moment you enter your card details, they’re managed and protected by the most trusted credit card processors in the industry: Stripe and Global Payments.
All Breathe accounts operate under the same terms and conditions.
We hate boring legal stuff, but it’s important you know how we operate. Read full T&Cs
Add an extra layer of security to yours and your team's Breathe accounts with our two-factor authentication (2FA) feature.
Choose who you'd like to switch 2FA on for - whether that's just your HR users, line managers or everyone. They'll then need to provide a code - as well as their password - each time they log in.
Since 2020, Breathe has been owned by Australian software provider ELMO (ASX:ELO), who were founded all the way back in 2002.
ELMO are the fastest-growing HR software company in the region and offer the only integrated HR, payroll & rota, time and attendance in Australia and New Zealand.
Your data is held in our highly secure data centre in London (as of 14th December 2020) where the data protection regulations are some best in the world. If you are a UK or Irish based company, rest assured that none of your data leaves the United Kingdom so you will comply with data protection regulations.
The security of your data is our number one priority. Breathe uses HTTPS encryption that ensures your data is always encrypted as it travels from our servers to your web browser.
A dedicated access server monitors, logs and controls all access to our data servers. It provides a single point of entry and ensures that your data can only be accessed from specific locations that we control. This process uses multiple layers of authentication and any attempt to access our servers from any other location will be denied and logged.
Our servers are held in a highly secure data centre in London that has complete CCTV coverage, motion sensors, reinforced access doors, controlled key storage systems, and an array of additional physical controls.
Beyond protecting your data at an infrastructure level, we are committed to the responsible use of AI within our platform. Our ISO 42001 accreditation means that wherever AI features appear in Breathe — from intelligent reporting to automated workflows — they are subject to the same rigour and oversight we apply to every other part of our security programme.
Breathe HR software is hosted in two independent secure locations both in the United Kingdom, the first in London, the second failover centre is in the UK. With data and code synchronised in real-time to both locations, Breathe has complete redundancy even in the event of a complete site failure.
The system is backed up on a daily basis to a third party location using industry-leading standards of security and encryption. Backups are kept for seven days. In addition, a backup is kept for the 1st of each month for three months. The backup includes all client data and documents.
It is very easy to import your employee data in to Breathe. Full instructions can be found at Breathe Support.
Yes, it is very simple to export your data from the application and your documents can be individually downloaded. If you have any questions just email our Support Team.
Yes - you'll have the option to switch this on within your settings. Once switched on, your people will need to provide a unique code from an authenticator app - as well as their usual password - each time they log in. This extra layer of security provides peace of mind and keeps your people's data extra-safe.
Yes. We were awarded ISO/IEC 42001:2023 accreditation in June 2026 — the international standard for Artificial Intelligence Management Systems. This certification confirms that an independent third party has validated how we govern the development and use of AI within our platform. It sits alongside our long-standing ISO 27001 information security certification. Together, they reflect our commitment to keeping your data secure and ensuring that the technology we build is ethical, transparent, and responsibly managed.