Legal
Security
Last updated: August 4, 2026
01Our security commitment
TeamHours holds the paper trail of your business: who worked, on what, for how long, and what you billed for it. We treat that data with the same care a ledger deserves — protected at rest and in transit, accessible only to the people you grant access, and recoverable when things go wrong.
This page describes our current security practices. If you need details for a security review, request our Security Summary or a signed DPA at security@teamhours.org.
02Encryption
In transit
All traffic to and from TeamHours is encrypted with TLS 1.2 or later (HTTPS only — we redirect all plain HTTP). Connections to our APIs and webhooks use the same protection.
At rest
All data stored in our databases and object storage is encrypted at rest using AES-256 or stronger. Backups are encrypted with the same standard and stored in separate, access-controlled infrastructure.
03Access controls
You control who sees what. TeamHours supports role-based access — owner, admin, member, and read-only roles — plus project-level permissions, so a contractor can log hours on a client project without seeing your billing rates or payroll data.
- Single sign-on (SSO) via SAML is available on higher plans, letting your organization control provisioning and deprovisioning centrally.
- Two-factor authentication (2FA) is available for every account and recommended for administrators. Workspaces can require it for all members.
- Password storage. Passwords are never stored in plaintext — only salted, slow-hashed values that cannot be reversed.
- Staff access. TeamHours staff access your data only to resolve support tickets you raise or to maintain the platform, under least-privilege and audited access rules.
04Audit trail
Workspaces keep an immutable audit log of meaningful events — logins, permission changes, budget edits, entry deletions, and settings modifications — with the actor, timestamp, and prior value. Administrators can review this log at any time, and exported reports include review timestamps so approvals can be traced end to end.
The audit log itself is append-only and cannot be edited or cleared by workspace members, including admins.
05Backups & availability
Production data is backed up continuously, with nightly snapshots retained for 90 days. Backups are stored in a different region from the primary data and are tested regularly through restore drills.
Our infrastructure runs across multiple availability zones, and we publish our service status at status.teamhours.org. We target 99.9% monthly uptime.
06Vulnerability handling
We run continuous dependency and code scanning, perform regular penetration tests, and review the OWASP Top 10 against every release. We maintain a public responsible disclosure policy: if you find a vulnerability, report it to security@teamhours.org with a reasonable disclosure window, and we will not pursue legal action for good-faith research.
07Incident response
If a security incident affects your data, we will notify the workspace owner by email within 72 hours of confirmation, describing what happened, what data was affected, and the steps we are taking. Critical incidents are communicated to affected workspaces before any public disclosure.
Every incident is followed by a root-cause review, and corrective actions are tracked to completion. A summary is available to customers on request.
08Compliance & data protection
We align our security program with SOC 2 Type II controls and GDPR/CCPA obligations for the data we process. Data is hosted in the United States by default; EU and UK customers can request EU data residency on eligible plans.
- DPA. A signed Data Processing Agreement incorporating Standard Contractual Clauses is available to all paying customers.
- Subprocessors. A current list of subprocessors is available on request and updated whenever the list changes.
- Deletion. On workspace deletion, data is erased from production immediately and from backups within 90 days.
09Reporting & contact
For security questions, incident reports, or vulnerability disclosures, contact security@teamhours.org. For privacy questions, see our Privacy Policy or write to privacy@teamhours.org.