SECURITY & COMPLIANCE

Security and Compliance in Time Management

See how we protect our customers and their data. For more information about our advanced data security practices, feel free to contact us.

CERTIFICATIONS

Security and Compliance Certifications

Our data collection and storage security is reinforced by certified processes, ensuring the reliability of our operations.

AICPA SOC 2

SOC 2

We comply with SOC 2 Type 2, adopting rigorous standards for security, availability, processing integrity, confidentiality, and privacy.

GDPR

GDPR

We meet GDPR (General Data Protection Regulation) standards, ensuring compliance with international data protection and privacy requirements.

INFRASTRUCTURE

Modern, secure infrastructure

Location

We use ISO 27001-certified data center facilities. Our services run on GCP (Google Cloud Platform), where data is hosted in the United States.

Physical security

Physical security is provided by Google, with ISO 27001-certified data center facilities and restricted, limited, controlled access.

OUR SOLUTIONS

Entry points and authentication

Entry points

We offer time-tracking and timesheet solutions built for mobile and Web, in multiple languages. Our app (iOS and Android) is customers' main entry point and connects to a backend hosted on multi-zone, high-availability Kubernetes clusters; our API is the entry point for external calls, hosted on Google Cloud Platform.

View API documentation โ†’

Access rights and user authentication

We use role-based security architecture and require every user to be identified and authenticated before using any system feature.

1

Local accounts: sign up with a valid email and password, with optional two-factor authentication.

2

Existing accounts: single sign-on with GitHub, Google, and Microsoft accounts.

3

SSO: corporate single sign-on is also available for Enterprise customers.

OPERATIONS

How we operate securely

Change management

A documented, regularly audited process with several stages of code review and quality assurance before any change reaches production. Customers are notified of significant changes in advance.

Session management

Sessions are managed server-side, implemented in the application's core code.

Automatic backup

Automatic, periodic backups of time records and other relevant information, minimizing data-loss risk and ensuring business continuity.

Reliability

Built with modern technologies that ensure business continuity across multiple layers, with rigorous encryption and access controls.

Internal audit logs

Audit logs from internal system components are collected in a separate environment, with access restricted to authorized users and retention from 6 months to several years.

Development environment

Development and test environments are hosted and access-controlled separately from production, with automated integration tests that also help catch security issues.

DATA SECURITY

How we handle your data

Processing personal information

We process and store a limited set of personal information solely for user authentication and authorization: name, gender, photo, password, address, biometric data, email, IP, cookies, and platform usage data.

Data handling

We follow information security best practices, storing data on Google Cloud with automated daily backups and 256-bit SSL certification, in line with ISO 27018 requirements.

Data backups

Daily backups, automatically tested through full restores, so the system can always be recovered in the event of a disaster. All backup procedures are documented and kept up to date.

HTTPS and HSTS

All communication is encrypted with up-to-date algorithms such as TLS 1.2, and we use HSTS to ensure the platform is always accessed over HTTPS.

Information collected

We collect information from individuals registered or authorized by the customer to access the platform, which may be used as evidence in cases of legal non-compliance or under court order.

See Privacy Policy โ†’

Access to customer data

Customer support and a limited number of DevOps team members can access customer data for support and troubleshooting.

Contract termination

After termination, all customer data (except what's legally required) is deleted from our systems, through an automated, documented process.

Data subject requests

Requests are handled manually, via in-app chat or by emailing [email protected].

Data anonymization

Outside specific advanced-troubleshooting cases, all customer data is anonymized through an in-house-built solution.

Data integrity

Ensured by database and file-system integrity checks, regular snapshots, encryption at rest, and point-in-time recovery backups.

Payment security

We use Stripe, a PCI DSS-certified payment processor, for payments. We do not retain credit card numbers or other financial data in our services.

CORPORATE SECURITY

Security across the organization

The integrity and protection of sensitive information sit at the core of our internal policies โ€” designed not just to meet, but to exceed regulatory and customer expectations.

Security team

A dedicated internal IT Security team working closely with Legal on compliance and data protection matters.

Security policies

Cybersecurity processes and policies aligned with leading security certifications โ€” log management, access management, vulnerability scanning, and ongoing user awareness โ€” all documented under our SOC 2 Type 2 certification.

Performance and monitoring

Internal solutions continuously monitor our systems, application availability, and other critical performance parameters.

Vulnerability management

An ongoing vulnerability-management process: server operating systems are regularly patched and updated, with internal processes to identify potential flaws.

Third-party risk management

We also assess risks introduced by third-party vendors and partners, to address or mitigate their potential impact.

Incident response

An established incident-response policy covering effective identification, remediation, investigation, prevention, and follow-up. Incidents can be reported to [email protected].

Human resources security

Every team member understands their information-security responsibilities and undergoes regular security-awareness training, minimizing the risk of human error.

Malware protection

All employee equipment is protected by antivirus software.

Internal risk management

Ongoing identification, assessment, and mitigation of risk, built into the company's normal management and oversight activities.

Responsible disclosure

We run vulnerability tests and pentests regularly, and can share results with customers on request.

Security question, or a vulnerability to report?

Talk to our support team โ€” we're happy to help.