Skip to main content
Security

Controls you can inspect, not vague promises.

A concise view of the safeguards in the product and production architecture, plus the boundaries customers should understand.

Last updated August 3, 2026. Save or print this page for your records.

Identity and access

Authentication uses secure, expiring email codes and WorkOS-managed sessions. Workspace roles and scoped server-side authorisation control access to records and actions. Tenant identifiers are derived from the authenticated membership rather than trusted from browser input.

Application and data protection

Production traffic is encrypted in transit. The application uses private, authenticated APIs, request-size limits, security headers, safe attachment handling, and tenant-scoped database queries. Sensitive API responses use private, no-store caching. PostgreSQL runs in a private AWS RDS network with encrypted storage and TLS connections.

Audit evidence

Timecard revisions, certifications, approvals, corrections, locks, and relevant administrative actions retain actor and timestamp evidence. Downloadable audit packages include integrity checks. These controls help demonstrate what happened; they are not a certification or a substitute for company policy and supervision.

Infrastructure and recovery

Production is deployed from immutable container images through short-lived AWS permissions. Secrets are kept outside source control. Database backups and encrypted infrastructure storage provide recovery layers. Restore procedures and access to destructive operations are controlled operational responsibilities that must be tested as part of production readiness.

Current assurance boundary

Timecard Lab does not currently claim SOC 2, ISO 27001, FedRAMP, CMMC, or DCAA certification, and this page is not a penetration-test report. We will state those claims only after the applicable independent process is complete. Procurement teams can request current architecture and security evidence.

Report a security concern

Send suspected vulnerabilities or security incidents to [email protected]. Include the affected URL, reproduction steps, and impact. Do not access another customer’s data or perform destructive testing.