Trust Center

Enterprise-grade security.
Included free. Every plan.

Other platforms charge $99-$490/year per site for security plugins. We include everything — Argon2id password hashing, breach detection, WAF, DDoS protection, CAPTCHA, brute force shield, audit logs — with every plan, at no extra cost. Because security shouldn't be a paid add-on.

Password Security

Military-grade password protection

Your passwords are protected by the most advanced hashing algorithm available today, with automatic breach monitoring.

🔐

Argon2id Hashing

Winner of the Password Hashing Competition (PHC). Memory-hard algorithm that is resistant to GPU, ASIC, and side-channel attacks. Every password is individually salted.

  • 64 MB memory cost per hash Makes brute-force attacks prohibitively expensive
  • 3 iterations with 2-way parallelism Optimal balance of security and performance
  • Automatic migration from legacy hashes on login Seamless upgrade without user intervention
🔍

HIBP Breach Detection

Integrated with Have I Been Pwned using the k-anonymity API. Passwords are checked against a database of over 900 million compromised credentials — without ever sending the password itself.

  • Real-time breach detection on registration and password change
  • Users warned immediately if password found in known data breaches
  • Privacy-preserving k-anonymity protocol Only a partial hash prefix is transmitted — your password never leaves the server
Authentication Protection

Multi-layered access control

Seven layers of protection between an attacker and your account. From invisible CAPTCHA to progressive lockout, every login attempt is evaluated in real time.

🤖

Invisible CAPTCHA

Cloudflare Turnstile provides privacy-first bot protection on login, registration, and password reset forms. No CAPTCHA puzzles — invisible verification that uses trust signals to let legitimate users through instantly while blocking automated attacks.

Adaptive Rate Limiting

Intelligent rate limiting that adjusts based on trust level. Trusted users with valid sessions experience no friction. Suspicious patterns trigger progressive throttling that slows attackers without blocking legitimate traffic.

🚫

Progressive Brute Force Lockout

Per-account protection with escalating lockout periods. After repeated failed attempts, the account is temporarily locked:

  • First lockout: 15 minutes
  • Second lockout: 1 hour
  • Persistent attacks: 24-hour lockout with admin notification
📱

Device Fingerprinting

Every login is associated with a device fingerprint. When a new device is detected, an email alert is sent to the account owner. Users can view and revoke active sessions from their security settings.

🔑

Multi-Factor Authentication (MFA)

Multiple second-factor options to suit every workflow. All MFA methods use time-limited codes with anti-replay protection.

  • TOTP (Time-based One-Time Password) Compatible with Google Authenticator, Authy, 1Password
  • Email verification codes
  • SMS verification codes
🌐

OAuth & SSO

Sign in with Google or Facebook. Enterprise customers can configure their own identity provider (BYOK — Bring Your Own Keys) for seamless SSO integration.

Infrastructure Security

Protected by industry leaders

Your data is protected by the same infrastructure that powers the world's largest websites. Personal and sensitive data stays exclusively in Canada (AWS Montreal). Published content is delivered globally via Cloudflare CDN for blazing-fast performance worldwide.

🛡️

AWS WAF (Web Application Firewall)

AWS-managed OWASP Top 10 rule sets protect every API endpoint. Blocks SQL injection, cross-site scripting (XSS), path traversal, and other common attack vectors automatically.

DDoS Protection

Dual-layer DDoS mitigation: AWS Shield Standard provides always-on network-layer protection, while Cloudflare's global network (330+ data centers) absorbs application-layer attacks before they reach your origin server.

🔒

SSL/HTTPS with HSTS Preload

Automatic SSL certificates for every site and custom domain. Zero-configuration, auto-renewed. HTTP Strict Transport Security (HSTS) with preload ensures browsers only connect via secure HTTPS — preventing SSL stripping attacks.

☁️

Cloudflare CDN with Zero-Trust Edge

All custom domains are proxied through Cloudflare's global network. Your origin server is never exposed. Edge caching, bot mitigation, and TLS termination happen at the network edge — closest to your visitors.

🇨🇦

Canadian Data Residency & Global CDN

All personal and sensitive data (accounts, databases, payments, secrets) is stored exclusively in AWS Canada (ca-central-1, Montreal). Published site content (pages, images, videos) is delivered globally via Cloudflare CDN for optimal performance. Full compliance with PIPEDA and Quebec's Loi 25. Additional regions (US, EU) available on demand for enterprise clients.

Security Headers

Defense-in-depth at the HTTP layer

Every response from TimingFlow includes a comprehensive set of security headers. These are configured automatically on every page you publish — zero configuration required.

🛡️

Content-Security-Policy

Strict CSP rules prevent cross-site scripting, data injection, and unauthorized resource loading.

🔒

HSTS with Preload

Forces all browsers to connect via HTTPS only. Included in browser preload lists for maximum protection.

🖼️

X-Frame-Options

Prevents clickjacking attacks by controlling whether your pages can be embedded in iframes.

📄

X-Content-Type-Options

Prevents MIME type sniffing. Ensures browsers respect declared content types, blocking script injection via mistyped resources.

🔗

Referrer-Policy

Controls how much referrer information is shared when users navigate away. Protects sensitive URL parameters.

🎛️

Permissions-Policy

Restricts access to browser features like camera, microphone, and geolocation. Only enabled when explicitly needed.

Subresource Integrity

SRI hash verification on all CDN-loaded resources. Ensures third-party scripts haven't been tampered with.

📋

Audit Logs

Every login, permission change, and admin action is logged with encrypted proof. 90-day retention, exportable for compliance.

Data Protection

Encrypted, backed up, isolated

Your data is encrypted at every stage, backed up continuously, and completely isolated from other tenants.

🔐

AES-256 Encryption at Rest

All data stored in DynamoDB, S3, and RDS is encrypted using AES-256 with AWS KMS-managed keys. Automatic key rotation ensures long-term security without operational overhead.

🔒

TLS 1.3 Encryption in Transit

All data in transit is encrypted using TLS 1.3 — the latest transport layer security protocol. Older TLS versions are disabled. Perfect forward secrecy ensures past sessions remain secure even if keys are compromised.

💾

Point-in-Time Recovery (35 Days)

DynamoDB Point-in-Time Recovery (PITR) is enabled on all tables, allowing restoration to any second within the last 35 days. Automated backups ensure no data is ever permanently lost.

🏢

Tenant Isolation

Complete data segregation per workspace. DynamoDB partition keys enforce logical isolation. PostgreSQL Row-Level Security (RLS) provides database-level tenant boundaries. One workspace can never access another's data.

App Studio Sites

Your published sites get the same protection

Every website, app, or form you build and publish with TimingFlow automatically inherits enterprise-grade security. Your end users are protected by the same controls that protect TimingFlow itself.

🔐

Argon2id Hashing

User accounts on your published sites use the same Argon2id hashing as the main platform.

🚫

Brute Force Shield

Progressive lockout protects every login form on every site you publish.

🤖

CAPTCHA & Rate Limiting

Cloudflare Turnstile and adaptive rate limiting on all authentication endpoints.

🛡️

SSL, Headers & WAF

Automatic HTTPS, full security headers, and WAF protection on every published page.

📊

Security Dashboard

Site owners get a security dashboard showing all active protections, security score, and recommendations.

🔗

Domain Security

WHOIS privacy, DNSSEC support, and automatic SSL for custom domains — all included free.

Built-in vs. Plugins

Why platform-level security wins

Traditional website builders rely on third-party security plugins that cost $99-$490/year per site, must be installed individually, and can be deactivated by any admin. TimingFlow takes a fundamentally different approach.

🔌

Traditional plugins

Per-site cost: $99-$490/year per site
Setup: Manual install + configuration on each site
Risk: Can be deactivated, outdated, or misconfigured
Scope: Only protects sites where installed
Plugins are the #1 attack vector — 60% of breaches exploit plugin vulnerabilities

🏗️

TimingFlow (built-in)

Cost: Included — no per-site fee
Setup: Automatic — zero configuration
Protection: Cannot be disabled or bypassed
Scope: Every site, every form, every API endpoint
No plugin system = no plugin attack surface

Compliance

Standards we meet

TimingFlow is built to meet the compliance requirements of regulated industries, healthcare providers, educational institutions, and privacy-conscious organizations.

🇨🇦

PIPEDA

Full compliance with Canada's Personal Information Protection and Electronic Documents Act.

⚖️

Loi 25 (Quebec)

Compliant with Quebec's Act Respecting the Protection of Personal Information in the Private Sector.

🇪🇺

GDPR Ready

Full data subject rights: access, rectification, erasure, portability. Consent management and DPA included.

WCAG 2.1 AA

Accessibility compliance built into the platform. AI-powered accessibility auditing helps you meet standards.

🛡️

SOC 2 Ready

Architecture and controls mapped to SOC 2 Type II requirements. Audit-ready documentation available on request.

👥

Role-Based Access

Granular RBAC with custom roles, per-page permissions, and workspace-level isolation. Full audit trail.

Trust

Security you can verify

We don't just claim security — we implement it at every layer. Here is a summary of the protections active on every TimingFlow account and published site.

🔐

Argon2id

Password Hashing
Competition Winner

🛡️

AWS WAF

OWASP Top 10
Protection

☁️

Cloudflare

330+ Edge
Data Centers

🔒

TLS 1.3

Latest Encryption
Protocol

🇨🇦

Canadian Hosted

AWS ca-central-1
Montreal

💾

35-Day PITR

Point-in-Time
Recovery

🔍

HIBP

Breach
Detection

⚖️

PIPEDA + Loi 25

Canadian Privacy
Compliance

Last updated: July 2026

Questions about security?

Our team is ready to discuss your security requirements, compliance needs, and data residency options. We can provide detailed documentation for your security audit.