Identity and access
Authentication uses secure, expiring email codes and WorkOS-managed sessions. Workspace roles and scoped server-side authorisation control access to records and actions. Tenant identifiers are derived from the authenticated membership rather than trusted from browser input.
Application and data protection
Production traffic is encrypted in transit. The application uses private, authenticated APIs, request-size limits, security headers, safe attachment handling, and tenant-scoped database queries. Sensitive API responses use private, no-store caching. PostgreSQL runs in a private AWS RDS network with encrypted storage and TLS connections.
Audit evidence
Timecard revisions, certifications, approvals, corrections, locks, and relevant administrative actions retain actor and timestamp evidence. Downloadable audit packages include integrity checks. These controls help demonstrate what happened; they are not a certification or a substitute for company policy and supervision.
Infrastructure and recovery
Production is deployed from immutable container images through short-lived AWS permissions. Secrets are kept outside source control. Database backups and encrypted infrastructure storage provide recovery layers. Restore procedures and access to destructive operations are controlled operational responsibilities that must be tested as part of production readiness.
Current assurance boundary
Timecard Lab does not currently claim SOC 2, ISO 27001, FedRAMP, CMMC, or DCAA certification, and this page is not a penetration-test report. We will state those claims only after the applicable independent process is complete. Procurement teams can request current architecture and security evidence.
Report a security concern
Send suspected vulnerabilities or security incidents to [email protected]. Include the affected URL, reproduction steps, and impact. Do not access another customer’s data or perform destructive testing.