Your data is safe with TimmyHR
We treat the security of your employees' data as a fundamental responsibility — not a checkbox. Here's exactly how we protect it.
SOC 2 Aligned
TimmyHR is built around SOC 2 principles — availability, confidentiality, processing integrity, security, and privacy. We operate with the controls of a trusted enterprise.
End-to-End Encryption
All data is encrypted in transit (TLS) and at rest. Your employees' information is protected at every stage — from the moment it's entered to the moment it's stored.
GDPR Ready
We support your GDPR obligations with role-based access, data export for a given employee, a full audit trail, and a Data Processing Agreement (DPA) available on request.
SSO & Identity
Single Sign-On via Google OAuth 2.0, plus optional two-factor authentication (authenticator app or backup codes) for every account. Email domain restriction ensures only authorised users can join your workspace.
Infrastructure Security
Hosted on a modern serverless cloud platform with automated backups and Neon PostgreSQL for reliability. Serverless scaling and connection pooling keep TimmyHR fast and dependable.
Audit Trails
Every sensitive action — payroll changes, permission updates, data exports — is logged with a timestamp and the user who made it, and kept as a complete record for admins.
Security checklist
Questions about our security practices?
Our security team is happy to provide a DPA, answer compliance questions, or walk through our controls with your IT team.
