Authentication
Active users sign in with company-issued accounts. Access tokens are short-lived, refresh sessions can be rotated or revoked, and inactive users or companies are blocked.
Gatula Time is designed around authenticated sessions, backend authorization, tenant isolation and traceable business actions.
Active users sign in with company-issued accounts. Access tokens are short-lived, refresh sessions can be rotated or revoked, and inactive users or companies are blocked.
Roles provide permissions, but permission checks alone are not enough. The backend also verifies company ownership and whether the user may access the specific record.
Important changes create audit records with the actor, action, entity, old and new values where appropriate, request context and timestamp.
Passwords are hashed. Raw refresh, reset and invitation tokens are not stored. Sensitive financial or employee fields are returned only to authorized roles.
Production deployment requires HTTPS, controlled origins, protected secrets, encrypted backups, private object storage and monitored background workers.
Gatula Time does not claim security certifications that have not been independently completed. Formal penetration testing and deployment review remain release gates before production use.