Other builders often sell security as plugins. TimingFlow includes the full security stack on every plan by default — Argon2id hashing, HIBP breach checks, Turnstile CAPTCHA, multi-factor authentication, progressive lockout, Cloudflare web application firewall (WAF) and rate limiting on the API, AES-256 encryption, role- and workspace-based access control, and tamper-evident audit logging. The only paid security upgrade is an optional dedicated KMS key for teams that need project-level cryptographic isolation.
Passwords are hashed with Argon2id (Password Hashing Competition winner) and checked against known breach corpora using privacy-preserving HIBP k-anonymity — without sending the full password off-server.
Winner of the Password Hashing Competition (PHC). Memory-hard algorithm that is resistant to GPU, ASIC, and side-channel attacks. Every password is individually salted.
Integrated with Have I Been Pwned using the k-anonymity API. Passwords are checked against a database of over 900 million compromised credentials — without ever sending the password itself.
Multiple controls sit between an attacker and your account. From invisible CAPTCHA to progressive lockout, login attempts are evaluated with rate limits and device signals.
Cloudflare Turnstile protects login, registration, password reset, and public forms. Verification is invisible in the large majority of cases; when Cloudflare can't confirm automatically, a visible "confirm you're human" challenge appears, with the option to retry. The server always requires a valid Turnstile token before it processes a login, signup, password reset, or public form submission.
Sign-in attempts are limited per IP address and email address: 5 attempts per 15 minutes, or 10 when Turnstile reports high trust.
Atomic per account+IP-pair protection with escalating lockout periods. After repeated failed attempts from the same IP, that IP is temporarily locked out for the account:
Every login is associated with a device fingerprint. When a new device is detected, an email alert is sent to the account owner. Users can view and revoke active sessions from their security settings.
Multiple second-factor options, chosen among the methods enabled for the account. TOTP is verified server-side (RFC 6238, ±1 step window) with anti-replay protection; every attempt is capped (5 tries per challenge, 10 per account / 15 min).
Sign in with Google, Microsoft, Facebook or Apple. On the Enterprise plan, a workspace can require single sign-on through its own identity provider (OpenID Connect) and provision users with SCIM 2.0. SSO applies only to an email domain the workspace has verified with a DNS TXT record.
Your data is protected by the same infrastructure that powers the world's largest websites. Core personal and application data — including health data — is hosted in Canada by default (AWS Montreal). Published content is delivered globally via the Cloudflare CDN for blazing-fast performance worldwide.
An hourly synthetic check ("canary") probes our API endpoints and a sample of published sites. Any backend exception, critical Turnstile failure, or regression is grouped on an incident board and pages our team by SMS — not logs that sit unread.
Automatic SSL certificates for every site and custom domain. Zero-configuration, auto-renewed. TLS 1.0 and 1.1 are refused (TLS 1.2 minimum) on the console, API, content CDN, and published sites. HTTP Strict Transport Security (HSTS) is sent with a 2-year max-age; on timingflow.io and its subdomains it also carries includeSubDomains and the preload directive.
The API runs through the Cloudflare network and is protected by Cloudflare's managed rule set (WAF), active in block mode, with a dedicated per-IP rate limit on login and authentication endpoints (/v1/auth/*).
The TimingFlow console, the API, and every site or app published with App Studio run through Cloudflare's global network — edge caching, TLS termination, and DDoS mitigation close to your visitors.
Default data residency: Canada — core personal and application data is hosted in AWS Canada (ca-central-1, Montréal). Published assets may be cached globally (Cloudflare CDN / R2) for speed. AI processing (AWS Bedrock) follows the project's data region under our AI data residency policy; some external AI sub-processors process non-sensitive content outside Canada and are disclosed on our Subprocessors page — health data is never sent to them. Canada (ca-central-1) is the only hosting region today; additional regions are on the roadmap. Designed for PIPEDA and Quebec Loi 25 expectations.
The console and the pages you publish are served with a standard set of HTTP security headers, applied automatically — no configuration required.
A Content-Security-Policy limits where scripts and other resources can load from, and which sites may frame your pages.
Tells browsers to use HTTPS only (2-year max-age). On timingflow.io: includeSubDomains and preload; submission to the browser preload list is in progress. Custom domains registered through TimingFlow get the same full header automatically; other custom domains get HSTS without includeSubDomains (you control those zones) until their owner turns on "HSTS preload-ready" in the domain settings.
Prevents clickjacking attacks by controlling whether your pages can be embedded in iframes.
Prevents MIME type sniffing. Ensures browsers respect declared content types, blocking script injection via mistyped resources.
Controls how much referrer information is shared when users navigate away. Protects sensitive URL parameters.
Turns off browser hardware features published sites do not use (USB, serial, HID, Bluetooth, MIDI) and interest-based ad topics.
Third-party scripts and stylesheets loaded from public CDNs are pinned to an exact version with an integrity hash, so a modified file is refused by the browser. Turnstile and Stripe.js, which their vendors update in place, are restricted by CSP instead.
Every role, permission, and sensitive workspace action is logged into a tamper-evident HMAC hash chain — any retroactive alteration of an entry breaks the chain and is detectable on verification. Kept at least 12 months (security events of health-sector workspaces: 7 years; health-data access logs: for the life of the project). Workspace owners and admins can export them as CSV or JSON.
Your data is encrypted at every stage, backed up continuously, and separated by workspace/project partitions with server-side access control enforced on every route.
Application data stores (including DynamoDB and object storage used by the platform) are encrypted at rest with AES-256 and AWS KMS-managed keys on the default path. Sensitive form answers can add AES-256-GCM envelope encryption so each protected record carries its own wrapped data key.
Client and API traffic is encrypted in transit; TLS 1.0 and 1.1 are refused on the console, API, content CDN, and published sites — only TLS 1.2 or newer is accepted. Forward secrecy protects past sessions if long-term keys are later rotated.
Form webhooks already travel over HTTPS. Owners can also enable AES-256-GCM content encryption so answers, user fields, and context leave TimingFlow as ciphertext. Routing fields (event, timestamp, form ID) stay readable; the receiving system decrypts with the shared webhook secret. Turn encryption on, send a test to a body viewer — you see ciphertext. Add the secret on the other side — the full payload appears. Ideal when the destination is not Bubble-native crypto (use a small Node/Worker decrypt step, or keep encryption off and rely on TLS + HMAC for Bubble).
DynamoDB Point-in-Time Recovery (PITR) is enabled on core platform tables so operators can restore to a second within the retention window. This is a platform resilience control — not a substitute for your own export and retention policies.
Workspaces and projects are segregated with DynamoDB partition design, with server-side access control enforced on every route. Four hierarchical roles (viewer / member / admin / owner) plus a catalog of named permissions (billing, members, modules, deletion, export…) determine what each person can do. Restricted "SendGrid-style" access (e.g. email management only) can be granted to an invited member without giving them admin rights. Creator-rank rule: nobody can delete a resource created by someone of a higher rank than their own — the workspace owner always can. Where PostgreSQL is used for published apps, row-level security (RLS) adds another boundary on top of application-level access control.
Deleting a workspace or project moves it to trash — recoverable for 30 days, like Google Drive or Microsoft 365. Immediate permanent deletion requires the owner role, exact name confirmation, and re-authentication (password, MFA code, or a recent login for OAuth/SSO accounts). TimingFlow's protected internal workspaces can never be trashed.
Every plan includes full platform encryption under TimingFlow’s managed keys — the default is already production-grade. Teams that need extra cryptographic isolation can add a dedicated KMS key per project (optional Enterprise layer on top of the included stack).
Default for all projects — full production security, not a limited tier. Sensitive fields and storage are protected with AES-256 using AWS KMS keys operated by TimingFlow, plus tenant isolation (partition keys, access rules / RLS where applicable).
Creates a customer-managed encryption key reserved for one App Studio project. Policy is strict: while active, encrypted project data is intended to live 100% under that dedicated key — not a permanent mix of keys.
Security above is not only for the TimingFlow console. Every website, app, or form you ship with App Studio runs on the same production stack — so your end users get enterprise-grade protection by default, without installing security plugins.
User accounts on your published sites use the same Argon2id hashing as the main platform.
Progressive lockout protects every login form on every site you publish.
Rate limits on member sign-in and password reset, plus Cloudflare Turnstile on sign-in forms that include it.
Automatic HTTPS (TLS 1.2+) and full security headers — HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy — on every published page.
Site owners get a security dashboard showing all active protections, security score, and recommendations.
Domains registered through TimingFlow use Cloudflare Registrar, which redacts WHOIS contact details where the registry allows it. Custom domains get automatic SSL.
Many website builders rely on third-party security plugins that are licensed per site, installed one by one, and can be deactivated by any admin. TimingFlow takes a different approach.
Per-site cost: often a yearly license for each site
Setup: Manual install + configuration on each site
Risk: Can be deactivated, outdated, or misconfigured
Scope: Only protects sites where installed
Every plugin adds code that must be kept up to date
Cost: Included — no per-site fee
Setup: Automatic — zero configuration
Protection: Core controls are part of the platform, not removable plugins
Scope: The platform and every site you publish
No plugin system = no third-party plugin code to patch
TimingFlow is built for organizations with privacy obligations. We describe what the platform supports; we do not claim certifications we do not hold.
Core data hosted in Canada; self-service access, rectification, portability and account deletion; a published sub-processor list.
Built-in tools: confidentiality incident register, JSON/CSV export, account deletion, cookie consent logged without IP, analytics without a persistent identifier before consent. See our privacy policy.
Self-service access, rectification, erasure and portability; request tool for site owners; consent logged. A Data Processing Agreement is available on request. EU data residency is not available.
Accessibility tooling aligned with WCAG 2.1 AA: AI-assisted audits and fix suggestions for the pages you build.
TimingFlow does not hold a SOC 2 or ISO 27001 certification. Our hosting providers (AWS, Cloudflare) hold their own certifications, which do not extend to TimingFlow.
Workspace roles (owner, admin, member, viewer), custom roles and permissions for your app's end users, and per-project access controls.
A summary of the protections active on TimingFlow accounts and published sites.
Password Hashing
Competition Winner
TOTP, email, SMS
+ backup codes
Managed rules
+ API rate limiting
TLS 1.0/1.1
refused
AWS ca-central-1
Montreal
Point-in-Time
Recovery
Breach
Detection
Built-in privacy
tools
Found a security issue in TimingFlow, a site built with App Studio, or our infrastructure? Email [email protected]. Describe reproduction steps, potential impact, and, if possible, a non-destructive proof of concept. We acknowledge receipt, keep you updated on progress, and avoid disclosing a vulnerability publicly before a fix ships. Please do not access another customer's data beyond what is strictly necessary to demonstrate the issue. Machine-readable details: /.well-known/security.txt.
Our team is ready to discuss your security requirements, compliance needs, and data residency options. We can provide detailed documentation for your security audit.