Security and Compliance in Time Management
See how we protect our customers and their data. For more information about our advanced data security practices, feel free to contact us.
Security and Compliance Certifications
Our data collection and storage security is reinforced by certified processes, ensuring the reliability of our operations.
SOC 2
We comply with SOC 2 Type 2, adopting rigorous standards for security, availability, processing integrity, confidentiality, and privacy.
GDPR
We meet GDPR (General Data Protection Regulation) standards, ensuring compliance with international data protection and privacy requirements.
Modern, secure infrastructure
Location
We use ISO 27001-certified data center facilities. Our services run on GCP (Google Cloud Platform), where data is hosted in the United States.
Physical security
Physical security is provided by Google, with ISO 27001-certified data center facilities and restricted, limited, controlled access.
Entry points and authentication
Entry points
We offer time-tracking and timesheet solutions built for mobile and Web, in multiple languages. Our app (iOS and Android) is customers' main entry point and connects to a backend hosted on multi-zone, high-availability Kubernetes clusters; our API is the entry point for external calls, hosted on Google Cloud Platform.
View API documentation โAccess rights and user authentication
We use role-based security architecture and require every user to be identified and authenticated before using any system feature.
Local accounts: sign up with a valid email and password, with optional two-factor authentication.
Existing accounts: single sign-on with GitHub, Google, and Microsoft accounts.
SSO: corporate single sign-on is also available for Enterprise customers.
How we operate securely
Change management
A documented, regularly audited process with several stages of code review and quality assurance before any change reaches production. Customers are notified of significant changes in advance.
Session management
Sessions are managed server-side, implemented in the application's core code.
Automatic backup
Automatic, periodic backups of time records and other relevant information, minimizing data-loss risk and ensuring business continuity.
Reliability
Built with modern technologies that ensure business continuity across multiple layers, with rigorous encryption and access controls.
Internal audit logs
Audit logs from internal system components are collected in a separate environment, with access restricted to authorized users and retention from 6 months to several years.
Development environment
Development and test environments are hosted and access-controlled separately from production, with automated integration tests that also help catch security issues.
How we handle your data
Processing personal information
We process and store a limited set of personal information solely for user authentication and authorization: name, gender, photo, password, address, biometric data, email, IP, cookies, and platform usage data.
Data handling
We follow information security best practices, storing data on Google Cloud with automated daily backups and 256-bit SSL certification, in line with ISO 27018 requirements.
Data backups
Daily backups, automatically tested through full restores, so the system can always be recovered in the event of a disaster. All backup procedures are documented and kept up to date.
HTTPS and HSTS
All communication is encrypted with up-to-date algorithms such as TLS 1.2, and we use HSTS to ensure the platform is always accessed over HTTPS.
Information collected
We collect information from individuals registered or authorized by the customer to access the platform, which may be used as evidence in cases of legal non-compliance or under court order.
See Privacy Policy โAccess to customer data
Customer support and a limited number of DevOps team members can access customer data for support and troubleshooting.
Contract termination
After termination, all customer data (except what's legally required) is deleted from our systems, through an automated, documented process.
Data subject requests
Requests are handled manually, via in-app chat or by emailing [email protected].
Data anonymization
Outside specific advanced-troubleshooting cases, all customer data is anonymized through an in-house-built solution.
Data integrity
Ensured by database and file-system integrity checks, regular snapshots, encryption at rest, and point-in-time recovery backups.
Payment security
We use Stripe, a PCI DSS-certified payment processor, for payments. We do not retain credit card numbers or other financial data in our services.
Security across the organization
The integrity and protection of sensitive information sit at the core of our internal policies โ designed not just to meet, but to exceed regulatory and customer expectations.
Security team
A dedicated internal IT Security team working closely with Legal on compliance and data protection matters.
Security policies
Cybersecurity processes and policies aligned with leading security certifications โ log management, access management, vulnerability scanning, and ongoing user awareness โ all documented under our SOC 2 Type 2 certification.
Performance and monitoring
Internal solutions continuously monitor our systems, application availability, and other critical performance parameters.
Vulnerability management
An ongoing vulnerability-management process: server operating systems are regularly patched and updated, with internal processes to identify potential flaws.
Third-party risk management
We also assess risks introduced by third-party vendors and partners, to address or mitigate their potential impact.
Incident response
An established incident-response policy covering effective identification, remediation, investigation, prevention, and follow-up. Incidents can be reported to [email protected].
Human resources security
Every team member understands their information-security responsibilities and undergoes regular security-awareness training, minimizing the risk of human error.
Malware protection
All employee equipment is protected by antivirus software.
Internal risk management
Ongoing identification, assessment, and mitigation of risk, built into the company's normal management and oversight activities.
Responsible disclosure
We run vulnerability tests and pentests regularly, and can share results with customers on request.
