Data exclusively in the European Union
All your company data — sessions, employee PII, leave requests, documents — is stored only on EU servers. Primary region: Frankfurt (DE), backup: Warsaw (PL). No US transfers, no Cloud Act, no Schrems II surprises.
Technical safeguards
TLS 1.3 + HSTS
All traffic HTTPS, Let’s Encrypt certificate + HSTS preload list.
AES-256 encryption at rest
PostgreSQL with TDE, keys rotated every 90 days via KMS.
Multi-tenant with Row-Level Security
PostgreSQL RLS guarantees that company A physically cannot see company B’s data.
2FA TOTP (Google Authenticator)
TOTP 2FA login, backup codes, can be enforced organisation-wide.
Audit log on every action
Every login, edit, export — in the log with IP, user-agent and user. Retention: 12 months.
3-2-1 backups
3 copies of data, 2 different media, 1 offsite (Warsaw). Tested monthly.
GDPR compliance
TimeHunter is GDPR-compliant by design. Available tools: employee data export (art. 15), right to erasure (art. 17), DPA ready to sign in the panel, Records of Processing (art. 30) auto-filled, ICO-style breach notification within 72h.
Penetration testing & security audits
TimeHunter undergoes an annual penetration test (external security partner) + automatic SAST/DAST in CI on every deploy. Pentest report available to Enterprise customers under NDA. Critical issues = 0 in last 4 tests. Bug bounty: €100-€1000 per report.
Annual pentest
OWASP Top 10, business logic, race conditions, auth bypass — all checked.
SAST/DAST in CI
Every commit goes through Snyk, npm audit, SonarQube — no critical findings = deploy.
Vulnerability disclosure policy
security@timehunter.pl + PGP key. SLA 24h ack, 30 days patch.
Compliance frameworks
TimeHunter aligns with major security frameworks. ISO 27001 — audit complete, certificate expected Q3 2026. SOC 2 Type II — in prep (Q1 2027). NIS2 (EU directive 2022/2555) — compliant as a digital service provider. ENISA “Cloud Security for SMEs” — full compliance.
Incident response — a plan for every scenario
Server down? Data breach? Admin lost 2FA? TimeHunter has documented runbooks for 12 incident scenarios. Response time: P0 (down/leak) = 15 min, P1 (degradation) = 1h, P2 (single user issue) = 4h. RTO = 4h, RPO = 15 min (backups every 15 min).
Frequently asked questions
Can I get a DPA to sign?
Do you have an ISO 27001 certificate?
What happens to data after contract termination?
Do you have password policy and enforced 2FA?
What happens on a breach report by an employee?
Can I see who edited employee data?
Try 14 days free
Start a 14-day trial. No card required, full functionality.