Last updated: January 19, 2025
At Hines Time, security is our top priority. We implement industry-leading security practices to protect your data, ensure privacy, and maintain the highest standards of compliance. Your trust is earned through transparency and robust security measures.
All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS) with 256-bit encryption.
All data stored in our databases is encrypted using AES-256 encryption.
Passwords are hashed using bcrypt with salt, making them impossible to reverse-engineer.
Hosted on enterprise-grade cloud infrastructure with 99.9% uptime SLA.
Automated daily backups with 30-day retention and point-in-time recovery.
Advanced DDoS mitigation and rate limiting to prevent abuse.
Granular permissions for Admin, Supervisor, and User roles.
Optional 2FA via Microsoft Authenticator with backup codes for account recovery.
Secure passwordless sign-in with Face ID, Touch ID, or fingerprint using WebAuthn standard.
Secure JWT tokens with automatic expiration and refresh mechanisms.
All actions are logged with timestamp, user, and details for compliance tracking.
24/7 system monitoring with automated alerts for security incidents.
Full audit trail of who edited time entries, when, and why.
Hines Time supports passwordless biometric authentication using the WebAuthn standard. This allows you to sign in securely using your device's built-in biometric sensors without typing a password.
Face ID or Touch ID
Fingerprint or Face Unlock
Touch ID
Windows Hello (Face, Fingerprint, PIN)
We are fully compliant with the General Data Protection Regulation (GDPR) for European customers:
We adhere to internationally recognized security standards:
Each company's data is completely isolated in the database. Company A cannot access Company B's data under any circumstances. All queries are filtered by company_id to ensure strict data segregation.
Location data is collected only with user consent and browser permission. It is used solely for job site verification and payroll accuracy. Location data is only accessible to company administrators and supervisors for legitimate business purposes.
Job photos and toolbox PDFs are stored securely on our servers with access restricted to authorized users within the company. Files are scanned for malware and validated for type/size before storage.
We never store your credit card information. All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We only store a secure token for subscription management.
In the unlikely event of a security incident, we have a comprehensive response plan:
We welcome security researchers and users to report potential vulnerabilities responsibly.
If you discover a security vulnerability, please email us at:
security@hinestime.com
Please include: Description of the vulnerability, steps to reproduce, potential impact, and your contact information. We commit to responding within 48 hours.
We carefully select third-party services that meet our security standards:
PCI DSS Level 1 certified, SOC 2 Type II compliant, handles billions in transactions annually
AWS SES and SNS for notifications, ISO 27001 certified, GDPR compliant
Open-source mapping, privacy-focused, no tracking cookies, GDPR compliant
Help us keep your account secure:
Our security team is here to help. Contact us for security inquiries, vulnerability reports, or to request our security whitepaper.
Security Team: security@hinestime.com
General Support: support@hinestime.com
Expected response time: Within 48 hours for security issues, 24 hours for critical vulnerabilities
Made with Emergent