Keeping your data secure and safe

This page describes the technical and organisational measures we use to protect your data. It is the detail referred to in clause 4.1 of our data processing agreement, and it sits alongside Annex II of that agreement, which states the same measures in contractual form.

Timen is provided by Template OÜ, a private limited company registered in the Republic of Estonia under registry code 14110689, VAT identification number EE101937247, with its registered office at Tornimäe tn 7-79, 10145 Tallinn, Estonia, trading as Timen. Security questions go to support@gettimen.com; suspected vulnerabilities are covered by our vulnerability disclosure policy.

Encryption

All access to the Service is over HTTPS with TLS. Requests made over plain HTTP are redirected to HTTPS, and HTTP Strict Transport Security is enforced, so browsers will not fall back. Connections to the database and to internal services are encrypted.

Database storage, files and backups are encrypted at rest by our infrastructure providers. Passwords are stored as salted bcrypt hashes and are never stored or transmitted in plain text. The access and refresh tokens for any accounting or import provider you connect are encrypted at the application layer as well, so they are unreadable in a database dump.

Access control: your team

  • Individual accounts with their own credentials - logins are not shared.
  • Role-based permissions for owners, admins and members, with per-person overrides for finer control.
  • Per-project access, so a person only sees the projects they have been given.
  • Single sign-on with Google and Apple.
  • Session management and sign-out.
  • Optional time locking, which closes a past period so members can no longer edit it.

You decide who has access to what, and you remain responsible for assigning roles and permissions appropriately and for promptly removing access for people who no longer need it.

Access control: Timen personnel

Access to production systems is limited to the small number of people who require it, is protected by multi-factor authentication, and is granted on a least-privilege basis. Access is revoked promptly when it is no longer required, and everyone with it is bound by confidentiality obligations. We do not routinely access, monitor or review the contents of customer accounts; we do so only where it is reasonably necessary, for example to provide support you have asked for, to investigate a security incident, or to comply with a legal obligation.

Tenant separation

Customer accounts are logically separated at the application layer. Every request is scoped to the authenticated user's team and to that user's project permissions, so one customer's data is never reachable from another's session.

Logging and monitoring

We run application error monitoring and performance monitoring. Authentication events are recorded, including the time of sign-in, the originating IP address and the browser and operating system used, so you can recognise your own sessions and spot one you do not recognise.

Secure development

The Service is built on a framework that provides protection against common web vulnerabilities including SQL injection, cross-site scripting, cross-site request forgery and clickjacking. Static security analysis and a dependency vulnerability audit run as part of every build. Dependencies are kept current, security updates are applied, and changes are reviewed before release.

Abuse prevention

Sign-in, signup and the API are rate limited per IP address and per account, and user-supplied content is sanitised before it is stored or displayed.

Connected accounts and third-party tokens

When you send an invoice to an accounting system, the token for that system is obtained for that one export and revoked at the provider as soon as the export finishes. Nothing is kept between exports, so a copy of our database contains no usable credential for your accounting books. Import sources work differently, because they sync on a schedule with nobody present to approve it, and keep their token until you disconnect them.

AI assistants and the MCP connector

Timen has no AI features of its own, and no part of your data is sent to an AI provider unless you connect one yourself. Our MCP server lets you connect an outside assistant such as ChatGPT or Claude to your own account. That connection is authorised with OAuth 2.1 and, at the point of connection, you choose whether it gets read-only access or read plus the ability to make changes. It then acts with exactly the permissions you already hold - it cannot reach a project or a person you could not reach yourself, and it is bound by your team's time lock in the same way you are.

Deleting a time entry through the connector is a two-step action: the server returns a preview of what would be deleted and writes nothing until the assistant sends back an explicit confirmation. That gate is enforced by Timen rather than by the assistant, so there is nothing for the assistant to talk its way around. Writes are capped per user per hour. Access tokens are short-lived, and you can revoke a connection at any time. What each request sends and what comes back is set out in our privacy policy.

Your data: export and deletion

You can export reports as CSV or PDF and invoices as PDF or CSV at any time, read your data as JSON through the API, delete individual records yourself, and delete your whole account from the Timen iPhone or Android app or through the API. Cancelling deletes your content immediately and irrevocably. There is no post-termination retrieval window, so export anything you want to keep before cancelling. Residual copies may persist in encrypted backups for a limited period and are overwritten in the ordinary course of the backup rotation.

Providers we rely on

We enter into written data protection terms with every provider that processes customer data, assess each one before engaging it, and publish the complete list in Annex III of the data processing agreement. We give at least 30 days' notice before adding or replacing one.

If something goes wrong

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours, describing what we know about the nature of the breach, its likely consequences, and the steps taken to address it. The full commitment is in clause 8 of the data processing agreement.

If you believe you have found a security vulnerability in Timen, please read our vulnerability disclosure policy first - it sets out how to report, what we need from you, what is in scope and what is not - and then report it to support@gettimen.com. We do not operate a bug bounty and do not pay for reports. Our machine-readable contact details are published at /.well-known/security.txt.

Infrastructure

Timen is hosted by Heroku, one of the leading provider of cloud computing platform-as-a-service, valued by customers for ease of use, automation, and reliability and durability. Heroku is owned by Salesforce.com and has been in production since June 2007.

Data Centers

The physical infrastructure is hosted and managed within Amazon's secure data centers and utilize the Amazon Web Service (AWS) technology. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon's data center operations have been accredited under:

  • ISO 27001
  • SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
  • PCI DSS Level 1
  • FISMA Moderate
  • Sarbanes-Oxley (SOX)

Physical Security

Heroku utilizes ISO 27001 and FISMA certified data centers managed by Amazon. Amazon has many years of experience in designing, constructing, and operating large-scale data centers. This experience has been applied to the AWS platform and infrastructure. AWS data centers are housed in nondescript facilities, and critical facilities have extensive setback and military grade perimeter control berms as well as other natural boundary protection. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, state of the art intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication no fewer than three times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. Amazon only provides data center access and information to employees who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, his or her access is immediately revoked, even if they continue to be an employee of Amazon or Amazon Web Services. All physical and electronic access to data centers by Amazon employees is logged and audited routinely.

Backups and databases

Our applications are automatically backed up as part of the deployment process on secure, access controlled, and redundant storage. We use these backups to deploy the application across the platform and to automatically bring the application back online in the event of an outage. Continuous Protection keeps data safe on our databases. Every change to your data is written to write-ahead logs, which are shipped to multi-datacenter, high-durability storage. In the unlikely event of unrecoverable hardware failure, these logs can be automatically 'replayed' to recover the database to within seconds of its last known state.

The platform

The platform is designed for stability, scaling, and inherently mitigates common issues that lead to outages while maintaining recovery capabilities. Our platform maintains redundancy to prevent single points of failure, is able to replace failed components, and utilizes multiple data centers designed for resiliency. In the case of an outage, the platform is deployed across multiple data centers using current system images and data is restored from backups.

Disaster recovery applications and databases

The platform we use automatically restores applications and databases in the case of an outage. The platform is designed to dynamically deploy applications within the cloud, monitor for failures, and recover failed platform components including customer applications and databases.

For additional information contact us at support@gettimen.com or see: Heroku Security Policy and AWS Security.

See also our privacy policy, data processing agreement, GDPR page and terms of service.

Last revised: September 10, 2026