Section 1
Security overview
TimeNova is designed with security and privacy principles in mind. The platform combines access controls, organization separation, monitoring-policy controls, operational safeguards, and desktop-agent protections to support B2B time tracking.
Section 2
Security principles
TimeNova security work is guided by practical principles that matter for workforce data.
- Limit access to the people and roles that need it.
- Separate customer organizations and project/client access.
- Make monitoring configurable and visible to administrators.
- Protect credentials and sessions across web and desktop use.
- Keep auditability and operational diagnostics available for accountability.
Section 3
Authentication and sessions
TimeNova uses password protection, session controls, logout invalidation, and optional multi-factor authentication to help protect account access. Password-reset and login flows are designed to reduce account-enumeration risk.
- Optional multi-factor authentication is available in the product.
- Administrators can remove users who should no longer access a workspace.
- Users should choose strong passwords and keep recovery channels secure.
Section 5
Desktop-agent safeguards
The desktop agent supports local work tracking, offline-first sync, screenshot capture when enabled, idle detection, and app/window context according to workspace policy.
Sensitive desktop credentials are protected using platform-supported secure storage where available, and local tracking records are scoped to the signed-in user.
Section 6
Privacy and monitoring controls
Monitoring settings are policy-driven. Administrators can configure screenshot behavior, idle handling, task restrictions, and window-tracking behavior. Activity tracking is designed around activity counts and work context, not keystroke content.
Section 7
Data protection
TimeNova protects workspace data with authenticated access, organization separation, controlled screenshot access, auditability, and operational safeguards. Screenshot access is designed to use time-limited access patterns rather than public permanent links.
Hosting regions, backup schedules, and infrastructure-specific encryption settings should be reviewed in private customer agreements or security documentation when needed.
Section 8
Operations, logging, and recovery
TimeNova includes operational logging, audit trails, background processing, cleanup jobs, reporting workflows, and health signals that help TimeNova operate and troubleshoot the service.
Backup, recovery, incident response, and vendor details may vary by deployment and should be reviewed privately for regulated or high-assurance environments.
Section 9
Secure development practices
TimeNova development includes automated checks and tests across important product areas such as authentication, organization isolation, sync, screenshots, policies, reports, billing, and desktop-agent behavior.
External assessment schedules, certification status, and vulnerability response commitments should be confirmed through official TimeNova security communications.
Section 10
Responsible disclosure
Security issues can be reported through official TimeNova support channels. Helpful reports include affected pages or workflows, steps to reproduce, potential impact, and any safe proof-of-concept details.
TimeNova will investigate credible reports, prioritize remediation based on severity, and communicate with affected customers as required by law and contract.
Section 11
Customer security responsibilities
Customers help protect their TimeNova workspaces by using strong passwords, enabling multi-factor authentication where appropriate, limiting administrator roles, removing departed users, reviewing client access, configuring monitoring policies carefully, and keeping endpoint devices patched.
Section 12
Security FAQ
Is TimeNova SOC 2 certified? No formal certification claim is made on this page.
Does TimeNova record keystrokes? TimeNova activity tracking is designed around activity counts and work-session context, not keystroke content.
Can screenshots be disabled? Yes. Screenshot behavior is controlled by workspace policy.
Does browser tracking store full page addresses? TimeNova is designed to focus on browser domains rather than full page addresses.