Security
What we do to protect your team's data
TimeVP handles information about how people spend their working time. That deserves a plain description of our practices, not a wall of badges. Here is what we do, and what we do not yet claim.
Practices
The basics, done consistently
Encrypted in transit
Traffic between your browser and TimeVP is encrypted over HTTPS. Plain HTTP requests are redirected, and the site sends strict transport security headers so browsers keep using HTTPS.
Access controls
Access to workspace data is limited to accounts that belong to that workspace, with permissions checked when data is requested rather than only hidden in the interface.
Least privilege
Access to production systems and customer data inside the company is limited to the people who need it for their role, and is removed when that need ends.
Secrets stay server-side
API tokens and other credentials live in server environment configuration. They are never shipped to the browser, and this site is built so that an accidental client import of server code fails the build.
Dependencies and updates
We keep our dependencies current and apply security updates to the software we run. This is routine maintenance, not a guarantee; it is listed here because it is a large share of real-world risk.
Data handling
Collect what the product needs, and no more
TimeVP records the time and activity data your workspace has chosen to track, and the account details needed to run it. What is collected, how it is used and how long it is kept is set out in our privacy policy.
Your workspace administrator controls tracking settings for their team. If you are an employee with questions about what your employer tracks, they are the right first contact; we are happy to help them answer.
Responsible disclosure
Found a vulnerability? Tell us.
Email hello@timevp.com with a description of the issue, the steps to reproduce it and, if relevant, the account or URL involved. We will acknowledge the report, keep you informed while we investigate, and credit you if you would like us to once it is fixed.
Please do not access other people’s data, run automated scanners against production, or disclose the issue publicly before we have had a reasonable chance to fix it. We do not currently run a paid bug bounty programme.
Report a vulnerabilityCertifications and compliance
TimeVP does not currently hold, and does not claim, any third-party security or privacy certification. We do not describe ourselves as SOC 2, ISO 27001, HIPAA or GDPR certified. When independent audits or attestations are completed, they will be listed here with their scope and date.
PLACEHOLDER: certifications, when available