Trust Center

Enterprise-grade security.
Full stack on every plan.

Other builders often sell security as plugins. TimingFlow includes the full security stack on every plan by default — Argon2id hashing, HIBP breach checks, Turnstile CAPTCHA, multi-factor authentication, progressive lockout, Cloudflare web application firewall (WAF) and rate limiting on the API, AES-256 encryption, role- and workspace-based access control, and tamper-evident audit logging. The only paid security upgrade is an optional dedicated KMS key for teams that need project-level cryptographic isolation.

Password Security

Modern password protection

Passwords are hashed with Argon2id (Password Hashing Competition winner) and checked against known breach corpora using privacy-preserving HIBP k-anonymity — without sending the full password off-server.

🔐

Argon2id Hashing

Winner of the Password Hashing Competition (PHC). Memory-hard algorithm that is resistant to GPU, ASIC, and side-channel attacks. Every password is individually salted.

  • 64 MB memory cost per hash Makes brute-force attacks prohibitively expensive
  • 3 iterations with 2-way parallelism Optimal balance of security and performance
  • Automatic migration from legacy hashes on login Seamless upgrade without user intervention
🔍

HIBP Breach Detection

Integrated with Have I Been Pwned using the k-anonymity API. Passwords are checked against a database of over 900 million compromised credentials — without ever sending the password itself.

  • Checked at sign-up, sign-in, password change and password reset
  • Users warned immediately if password found in known data breaches
  • Privacy-preserving k-anonymity protocol Only a partial hash prefix is transmitted — your password never leaves the server
Authentication Protection

Multi-layered access control

Multiple controls sit between an attacker and your account. From invisible CAPTCHA to progressive lockout, login attempts are evaluated with rate limits and device signals.

🤖

Invisible CAPTCHA

Cloudflare Turnstile protects login, registration, password reset, and public forms. Verification is invisible in the large majority of cases; when Cloudflare can't confirm automatically, a visible "confirm you're human" challenge appears, with the option to retry. The server always requires a valid Turnstile token before it processes a login, signup, password reset, or public form submission.

⚡

Rate Limiting

Sign-in attempts are limited per IP address and email address: 5 attempts per 15 minutes, or 10 when Turnstile reports high trust.

🚫

Progressive Brute Force Lockout

Atomic per account+IP-pair protection with escalating lockout periods. After repeated failed attempts from the same IP, that IP is temporarily locked out for the account:

  • First lockout: 15 minutes
  • Second lockout: 1 hour
  • Persistent attacks: 24-hour lockout
  • Past 50 failures in 1 hour across all IPs, login requires a verified Turnstile token (never a permanent lock for the legitimate owner)
📱

Device Fingerprinting

Every login is associated with a device fingerprint. When a new device is detected, an email alert is sent to the account owner. Users can view and revoke active sessions from their security settings.

🔑

Multi-Factor Authentication (MFA)

Multiple second-factor options, chosen among the methods enabled for the account. TOTP is verified server-side (RFC 6238, ±1 step window) with anti-replay protection; every attempt is capped (5 tries per challenge, 10 per account / 15 min).

  • TOTP (Time-based One-Time Password) Compatible with Google Authenticator, Authy, 1Password
  • Email verification codes
  • SMS verification codes
  • Single-use backup codes Randomly generated, stored hashed, each works exactly once
🌐

OAuth & SSO

Sign in with Google, Microsoft, Facebook or Apple. On the Enterprise plan, a workspace can require single sign-on through its own identity provider (OpenID Connect) and provision users with SCIM 2.0. SSO applies only to an email domain the workspace has verified with a DNS TXT record.

Infrastructure Security

Protected by industry leaders

Your data is protected by the same infrastructure that powers the world's largest websites. Core personal and application data — including health data — is hosted in Canada by default (AWS Montreal). Published content is delivered globally via the Cloudflare CDN for blazing-fast performance worldwide.

📡

Automated monitoring & alerting

An hourly synthetic check ("canary") probes our API endpoints and a sample of published sites. Any backend exception, critical Turnstile failure, or regression is grouped on an incident board and pages our team by SMS — not logs that sit unread.

🔒

SSL/HTTPS with HSTS

Automatic SSL certificates for every site and custom domain. Zero-configuration, auto-renewed. TLS 1.0 and 1.1 are refused (TLS 1.2 minimum) on the console, API, content CDN, and published sites. HTTP Strict Transport Security (HSTS) is sent with a 2-year max-age; on timingflow.io and its subdomains it also carries includeSubDomains and the preload directive.

🛡️

Web application firewall & rate limiting (API)

The API runs through the Cloudflare network and is protected by Cloudflare's managed rule set (WAF), active in block mode, with a dedicated per-IP rate limit on login and authentication endpoints (/v1/auth/*).

☁️

Cloudflare network & DDoS protection

The TimingFlow console, the API, and every site or app published with App Studio run through Cloudflare's global network — edge caching, TLS termination, and DDoS mitigation close to your visitors.

🇨🇦

Canadian Data Residency & Global CDN

Default data residency: Canada — core personal and application data is hosted in AWS Canada (ca-central-1, Montréal). Published assets may be cached globally (Cloudflare CDN / R2) for speed. AI processing (AWS Bedrock) follows the project's data region under our AI data residency policy; some external AI sub-processors process non-sensitive content outside Canada and are disclosed on our Subprocessors page — health data is never sent to them. Canada (ca-central-1) is the only hosting region today; additional regions are on the roadmap. Designed for PIPEDA and Quebec Loi 25 expectations.

Security Headers

Defense-in-depth at the HTTP layer

The console and the pages you publish are served with a standard set of HTTP security headers, applied automatically — no configuration required.

🛡️

Content-Security-Policy

A Content-Security-Policy limits where scripts and other resources can load from, and which sites may frame your pages.

🔒

HSTS with Preload Directive

Tells browsers to use HTTPS only (2-year max-age). On timingflow.io: includeSubDomains and preload; submission to the browser preload list is in progress. Custom domains registered through TimingFlow get the same full header automatically; other custom domains get HSTS without includeSubDomains (you control those zones) until their owner turns on "HSTS preload-ready" in the domain settings.

🖼️

X-Frame-Options

Prevents clickjacking attacks by controlling whether your pages can be embedded in iframes.

📄

X-Content-Type-Options

Prevents MIME type sniffing. Ensures browsers respect declared content types, blocking script injection via mistyped resources.

🔗

Referrer-Policy

Controls how much referrer information is shared when users navigate away. Protects sensitive URL parameters.

🎛️

Permissions-Policy

Turns off browser hardware features published sites do not use (USB, serial, HID, Bluetooth, MIDI) and interest-based ad topics.

✅

Subresource Integrity

Third-party scripts and stylesheets loaded from public CDNs are pinned to an exact version with an integrity hash, so a modified file is refused by the browser. Turnstile and Stripe.js, which their vendors update in place, are restricted by CSP instead.

📋

Audit Logs

Every role, permission, and sensitive workspace action is logged into a tamper-evident HMAC hash chain — any retroactive alteration of an entry breaks the chain and is detectable on verification. Kept at least 12 months (security events of health-sector workspaces: 7 years; health-data access logs: for the life of the project). Workspace owners and admins can export them as CSV or JSON.

Data Protection

Encrypted, backed up, strict access control

Your data is encrypted at every stage, backed up continuously, and separated by workspace/project partitions with server-side access control enforced on every route.

🔐

AES-256 encryption at rest

Application data stores (including DynamoDB and object storage used by the platform) are encrypted at rest with AES-256 and AWS KMS-managed keys on the default path. Sensitive form answers can add AES-256-GCM envelope encryption so each protected record carries its own wrapped data key.

🔒

TLS 1.2+ in transit

Client and API traffic is encrypted in transit; TLS 1.0 and 1.1 are refused on the console, API, content CDN, and published sites — only TLS 1.2 or newer is accepted. Forward secrecy protects past sessions if long-term keys are later rotated.

🔐

Optional webhook payload encryption

Form webhooks already travel over HTTPS. Owners can also enable AES-256-GCM content encryption so answers, user fields, and context leave TimingFlow as ciphertext. Routing fields (event, timestamp, form ID) stay readable; the receiving system decrypts with the shared webhook secret. Turn encryption on, send a test to a body viewer — you see ciphertext. Add the secret on the other side — the full payload appears. Ideal when the destination is not Bubble-native crypto (use a small Node/Worker decrypt step, or keep encryption off and rely on TLS + HMAC for Bubble).

💾

Point-in-time recovery (35 days)

DynamoDB Point-in-Time Recovery (PITR) is enabled on core platform tables so operators can restore to a second within the retention window. This is a platform resilience control — not a substitute for your own export and retention policies.

🏢

Roles, named permissions & creator-rank rule

Workspaces and projects are segregated with DynamoDB partition design, with server-side access control enforced on every route. Four hierarchical roles (viewer / member / admin / owner) plus a catalog of named permissions (billing, members, modules, deletion, export…) determine what each person can do. Restricted "SendGrid-style" access (e.g. email management only) can be granted to an invited member without giving them admin rights. Creator-rank rule: nobody can delete a resource created by someone of a higher rank than their own — the workspace owner always can. Where PostgreSQL is used for published apps, row-level security (RLS) adds another boundary on top of application-level access control.

🗑️

Trash & recovery (30 days)

Deleting a workspace or project moves it to trash — recoverable for 30 days, like Google Drive or Microsoft 365. Immediate permanent deletion requires the owner role, exact name confirmation, and re-authentication (password, MFA code, or a recent login for OAuth/SSO accounts). TimingFlow's protected internal workspaces can never be trashed.

Encryption keys

Two key models. Clear by design.

Every plan includes full platform encryption under TimingFlow’s managed keys — the default is already production-grade. Teams that need extra cryptographic isolation can add a dedicated KMS key per project (optional Enterprise layer on top of the included stack).

The full security stack (edge, auth, isolation, platform encryption) is included on every plan. The dedicated customer KMS key is the optional paid add-on. Activating or later removing it may require a one-time data transfer priced by how many encrypted records must be re-keyed.
Included · every plan

Platform encryption key

Default for all projects — full production security, not a limited tier. Sensitive fields and storage are protected with AES-256 using AWS KMS keys operated by TimingFlow, plus tenant isolation (partition keys, access rules / RLS where applicable).

  • No extra monthly fee for this default path
  • Isolation is logical (workspace / project / roles) + encryption
  • Form submissions can use AES-256-GCM envelope encryption (unique data key material per record where enabled)
  • Best for most apps, including production sites
Optional · Enterprise add-on

Dedicated project KMS key

Creates a customer-managed encryption key reserved for one App Studio project. Policy is strict: while active, encrypted project data is intended to live 100% under that dedicated key — not a permanent mix of keys.

  • Monthly subscription per project (shown in-product before you confirm)
  • New / low-volume projects may have $0 migration; larger histories show a clear one-time transfer fee
  • Disabling later is not a simple cancel: data must be transferred back under the platform key first — cost can grow as your database grows
  • The dedicated key is not deleted until transfer completes successfully
Important: A dedicated key improves cryptographic isolation for that project’s encrypted data. It does not replace access control, backups, or your own operational security. TimingFlow holds no SOC 2 or ISO 27001 certification.
App Studio Sites

Apps you build in App Studio are fully protected

Security above is not only for the TimingFlow console. Every website, app, or form you ship with App Studio runs on the same production stack — so your end users get enterprise-grade protection by default, without installing security plugins.

🔐

Argon2id Hashing

User accounts on your published sites use the same Argon2id hashing as the main platform.

🚫

Brute Force Shield

Progressive lockout protects every login form on every site you publish.

🤖

CAPTCHA & Rate Limiting

Rate limits on member sign-in and password reset, plus Cloudflare Turnstile on sign-in forms that include it.

🛡️

SSL & Security Headers

Automatic HTTPS (TLS 1.2+) and full security headers — HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy — on every published page.

📊

Security Dashboard

Site owners get a security dashboard showing all active protections, security score, and recommendations.

🔗

Domain Security

Domains registered through TimingFlow use Cloudflare Registrar, which redacts WHOIS contact details where the registry allows it. Custom domains get automatic SSL.

Built-in vs. Plugins

Why platform-level security helps

Many website builders rely on third-party security plugins that are licensed per site, installed one by one, and can be deactivated by any admin. TimingFlow takes a different approach.

🔌

Traditional plugins

Per-site cost: often a yearly license for each site
Setup: Manual install + configuration on each site
Risk: Can be deactivated, outdated, or misconfigured
Scope: Only protects sites where installed
Every plugin adds code that must be kept up to date

🏗️

TimingFlow (built-in)

Cost: Included — no per-site fee
Setup: Automatic — zero configuration
Protection: Core controls are part of the platform, not removable plugins
Scope: The platform and every site you publish
No plugin system = no third-party plugin code to patch

Compliance

Privacy and compliance — where we stand

TimingFlow is built for organizations with privacy obligations. We describe what the platform supports; we do not claim certifications we do not hold.

🇨🇦

PIPEDA

Core data hosted in Canada; self-service access, rectification, portability and account deletion; a published sub-processor list.

⚖️

Loi 25 (Quebec)

Built-in tools: confidentiality incident register, JSON/CSV export, account deletion, cookie consent logged without IP, analytics without a persistent identifier before consent. See our privacy policy.

🇪🇺

GDPR

Self-service access, rectification, erasure and portability; request tool for site owners; consent logged. A Data Processing Agreement is available on request. EU data residency is not available.

♿

WCAG 2.1 AA

Accessibility tooling aligned with WCAG 2.1 AA: AI-assisted audits and fix suggestions for the pages you build.

🛡️

No SOC 2 certification

TimingFlow does not hold a SOC 2 or ISO 27001 certification. Our hosting providers (AWS, Cloudflare) hold their own certifications, which do not extend to TimingFlow.

👥

Role-Based Access

Workspace roles (owner, admin, member, viewer), custom roles and permissions for your app's end users, and per-project access controls.

Trust

At a glance

A summary of the protections active on TimingFlow accounts and published sites.

🔐

Argon2id

Password Hashing
Competition Winner

🔑

MFA

TOTP, email, SMS
+ backup codes

🛡️

Cloudflare WAF

Managed rules
+ API rate limiting

🔒

TLS 1.2+

TLS 1.0/1.1
refused

🇨🇦

Core Data in Canada

AWS ca-central-1
Montreal

💾

35-Day PITR

Point-in-Time
Recovery

🔍

HIBP

Breach
Detection

⚖️

PIPEDA + Loi 25

Built-in privacy
tools

Last verified: September 2026 — the technical claims above are checked against the code and the production environment by an automated script · Sub-processors
Responsible Disclosure

Report a vulnerability

Found a security issue in TimingFlow, a site built with App Studio, or our infrastructure? Email [email protected]. Describe reproduction steps, potential impact, and, if possible, a non-destructive proof of concept. We acknowledge receipt, keep you updated on progress, and avoid disclosing a vulnerability publicly before a fix ships. Please do not access another customer's data beyond what is strictly necessary to demonstrate the issue. Machine-readable details: /.well-known/security.txt.

Questions about security?

Our team is ready to discuss your security requirements, compliance needs, and data residency options. We can provide detailed documentation for your security audit.