Your clients' time, invoices, and messages run through Timebun — we take protecting that data seriously. Here's how.
Infrastructure
Timebun runs on reputable cloud infrastructure rather than our own physical servers, so it inherits the physical and network security controls of established providers.
Encryption
All traffic between your browser and Timebun is encrypted in transit over HTTPS. Data is encrypted at rest using industry-standard methods.
Access controls
Access to your workspace is invitation-only — nobody can self-register into your account. Within a workspace, permissions (like visibility into cost and margin data) are role-based, so sensitive figures aren't exposed to everyone by default.
Payments
All payments and card details are handled directly by Stripe, a PCI-DSS Level 1 certified payment processor. Timebun never stores your clients' full card numbers.
Backups & availability
Your data is backed up regularly, and we monitor the Service for uptime and respond to incidents as they arise.
Responsible disclosure
If you believe you've found a security vulnerability in Timebun, please tell us before disclosing it publicly. Email security@timebun.com with details and we'll respond as quickly as we can.
Questions
For anything else security-related, reach us at security@timebun.com.

