Skip to content

Security

Last updated 27 September 2026

Accounts and access

  • Passwords are stored only as salted scrypt hashes.
  • Sign in with Google is available; you can restrict it to your Google Workspace domain.
  • Session cookies are HttpOnly and SameSite=Lax.
  • Role-based access (owner, admin, manager, member) is enforced on the server and inside database queries, not just hidden in the interface.
  • API tokens are random 256-bit values stored only as SHA-256 hashes, shown once, revocable, and unable to create other tokens.
  • The Mac app signs in through your browser with a single-use, two-minute code delivered to your own machine (RFC 8252 loopback), and holds its own revocable session.
  • The iPhone app keeps its session in the iOS Keychain. Google sign-in runs in Apple's authentication sheet and returns a single-use code bound to the app with PKCE (RFC 7636); Sign in with Apple uses Apple's signed identity token with a one-time nonce. Stored files open through five-minute signed links, so the app's session never leaves Hourtick's servers.

Data integrity

  • Every change to time data is validated by the same rules on client and server and recorded in an append-only event log.
  • Invoiced, submitted and approved time is locked on the server, so it can't be changed even by devices replaying offline edits.
  • The database guarantees one running timer per person and uses versioning to prevent lost updates.

Infrastructure

  • All traffic is encrypted with TLS in production.
  • Payment data is handled by Stripe (PCI DSS Level 1); card numbers never reach our servers.
  • Webhooks are signature-verified.
  • Application servers and the PostgreSQL database run on Akamai Cloud (Linode), Frankfurt, Germany, so workspace data is stored in the EU. Uploaded files are stored in the EU as well, or in the United States for workspaces whose admin chooses US file storage.

Privacy by design

No screenshots, keystroke logging, app tracking or location tracking. No analytics or advertising cookies in the app; Google Analytics runs on our public website only with the visitor's consent.

Responsible disclosure

Found a vulnerability? Send it through the contact form (topic “Security report”) with details and steps to reproduce. Please give us reasonable time to fix it before disclosing, and don't access data that isn't yours. We won't take legal action against good-faith research that follows these rules.

Send us a message. The topic is already chosen, change it if you like.

We only use your details to answer you. See our privacy policy.