Your clients' time, invoices, and messages run through Timebun — we take protecting that data seriously. Here's how.

Infrastructure

Timebun runs on reputable cloud infrastructure rather than our own physical servers, so it inherits the physical and network security controls of established providers.

Encryption

All traffic between your browser and Timebun is encrypted in transit over HTTPS. Data is encrypted at rest using industry-standard methods.

Access controls

Access to your workspace is invitation-only — nobody can self-register into your account. Within a workspace, permissions (like visibility into cost and margin data) are role-based, so sensitive figures aren't exposed to everyone by default.

Payments

All payments and card details are handled directly by Stripe, a PCI-DSS Level 1 certified payment processor. Timebun never stores your clients' full card numbers.

Backups & availability

Your data is backed up regularly, and we monitor the Service for uptime and respond to incidents as they arise.

Responsible disclosure

If you believe you've found a security vulnerability in Timebun, please tell us before disclosing it publicly. Email security@timebun.com with details and we'll respond as quickly as we can.

Questions

For anything else security-related, reach us at security@timebun.com.