Skip to content
Read how TimeVP thinks about productivity without surveillanceRead the blog

Security

What we do to protect your team's data

TimeVP handles information about how people spend their working time. That deserves a plain description of our practices, not a wall of badges. Here is what we do, and what we do not yet claim.

Practices

The basics, done consistently

  • Encrypted in transit

    Traffic between your browser and TimeVP is encrypted over HTTPS. Plain HTTP requests are redirected, and the site sends strict transport security headers so browsers keep using HTTPS.

  • Access controls

    Access to workspace data is limited to accounts that belong to that workspace, with permissions checked when data is requested rather than only hidden in the interface.

  • Least privilege

    Access to production systems and customer data inside the company is limited to the people who need it for their role, and is removed when that need ends.

  • Secrets stay server-side

    API tokens and other credentials live in server environment configuration. They are never shipped to the browser, and this site is built so that an accidental client import of server code fails the build.

  • Dependencies and updates

    We keep our dependencies current and apply security updates to the software we run. This is routine maintenance, not a guarantee; it is listed here because it is a large share of real-world risk.

Data handling

Collect what the product needs, and no more

TimeVP records the time and activity data your workspace has chosen to track, and the account details needed to run it. What is collected, how it is used and how long it is kept is set out in our privacy policy.

Your workspace administrator controls tracking settings for their team. If you are an employee with questions about what your employer tracks, they are the right first contact; we are happy to help them answer.

Responsible disclosure

Found a vulnerability? Tell us.

Email hello@timevp.com with a description of the issue, the steps to reproduce it and, if relevant, the account or URL involved. We will acknowledge the report, keep you informed while we investigate, and credit you if you would like us to once it is fixed.

Please do not access other people’s data, run automated scanners against production, or disclose the issue publicly before we have had a reasonable chance to fix it. We do not currently run a paid bug bounty programme.

Report a vulnerability

Certifications and compliance

TimeVP does not currently hold, and does not claim, any third-party security or privacy certification. We do not describe ourselves as SOC 2, ISO 27001, HIPAA or GDPR certified. When independent audits or attestations are completed, they will be listed here with their scope and date.

PLACEHOLDER: certifications, when available