Security at TimeNova

Designed for accountable, privacy-aware time tracking

How TimeNova approaches authentication, access control, desktop-agent safeguards, monitoring transparency, and customer security responsibilities.

Last updated July 17, 2026

At a glance

Access

Workspace roles and project permissions help limit sensitive data exposure.

Monitoring

Screenshot, idle, and activity controls are policy-driven.

Disclosure

Security issues can be reported through official TimeNova support channels.

Section 1

Security overview

TimeNova is designed with security and privacy principles in mind. The platform combines access controls, organization separation, monitoring-policy controls, operational safeguards, and desktop-agent protections to support B2B time tracking.

Section 2

Security principles

TimeNova security work is guided by practical principles that matter for workforce data.

  • Limit access to the people and roles that need it.
  • Separate customer organizations and project/client access.
  • Make monitoring configurable and visible to administrators.
  • Protect credentials and sessions across web and desktop use.
  • Keep auditability and operational diagnostics available for accountability.

Section 3

Authentication and sessions

TimeNova uses password protection, session controls, logout invalidation, and optional multi-factor authentication to help protect account access. Password-reset and login flows are designed to reduce account-enumeration risk.

  • Optional multi-factor authentication is available in the product.
  • Administrators can remove users who should no longer access a workspace.
  • Users should choose strong passwords and keep recovery channels secure.

Section 4

Authorization and data separation

TimeNova uses workspace roles, organization membership, project access, and client-access settings to limit what each user can view or manage.

  • Owners, admins, managers, employees, and clients have different access levels.
  • Client users can be restricted to selected projects and visibility options.
  • Administrative actions and sensitive views should be limited to appropriate roles.

Section 5

Desktop-agent safeguards

The desktop agent supports local work tracking, offline-first sync, screenshot capture when enabled, idle detection, and app/window context according to workspace policy.

Sensitive desktop credentials are protected using platform-supported secure storage where available, and local tracking records are scoped to the signed-in user.

Section 6

Privacy and monitoring controls

Monitoring settings are policy-driven. Administrators can configure screenshot behavior, idle handling, task restrictions, and window-tracking behavior. Activity tracking is designed around activity counts and work context, not keystroke content.

Section 7

Data protection

TimeNova protects workspace data with authenticated access, organization separation, controlled screenshot access, auditability, and operational safeguards. Screenshot access is designed to use time-limited access patterns rather than public permanent links.

Hosting regions, backup schedules, and infrastructure-specific encryption settings should be reviewed in private customer agreements or security documentation when needed.

Section 8

Operations, logging, and recovery

TimeNova includes operational logging, audit trails, background processing, cleanup jobs, reporting workflows, and health signals that help TimeNova operate and troubleshoot the service.

Backup, recovery, incident response, and vendor details may vary by deployment and should be reviewed privately for regulated or high-assurance environments.

Section 9

Secure development practices

TimeNova development includes automated checks and tests across important product areas such as authentication, organization isolation, sync, screenshots, policies, reports, billing, and desktop-agent behavior.

External assessment schedules, certification status, and vulnerability response commitments should be confirmed through official TimeNova security communications.

Section 10

Responsible disclosure

Security issues can be reported through official TimeNova support channels. Helpful reports include affected pages or workflows, steps to reproduce, potential impact, and any safe proof-of-concept details.

TimeNova will investigate credible reports, prioritize remediation based on severity, and communicate with affected customers as required by law and contract.

Section 11

Customer security responsibilities

Customers help protect their TimeNova workspaces by using strong passwords, enabling multi-factor authentication where appropriate, limiting administrator roles, removing departed users, reviewing client access, configuring monitoring policies carefully, and keeping endpoint devices patched.

Section 12

Security FAQ

Is TimeNova SOC 2 certified? No formal certification claim is made on this page.

Does TimeNova record keystrokes? TimeNova activity tracking is designed around activity counts and work-session context, not keystroke content.

Can screenshots be disabled? Yes. Screenshot behavior is controlled by workspace policy.

Does browser tracking store full page addresses? TimeNova is designed to focus on browser domains rather than full page addresses.