Security and trust

Access is verified at every layer.

Gatula Time is designed around authenticated sessions, backend authorization, tenant isolation and traceable business actions.

01

Authentication

Active users sign in with company-issued accounts. Access tokens are short-lived, refresh sessions can be rotated or revoked, and inactive users or companies are blocked.

02

Authorization

Roles provide permissions, but permission checks alone are not enough. The backend also verifies company ownership and whether the user may access the specific record.

03

Auditability

Important changes create audit records with the actor, action, entity, old and new values where appropriate, request context and timestamp.

04

Data handling

Passwords are hashed. Raw refresh, reset and invitation tokens are not stored. Sensitive financial or employee fields are returned only to authorized roles.

05

Infrastructure

Production deployment requires HTTPS, controlled origins, protected secrets, encrypted backups, private object storage and monitored background workers.

06

Responsible scope

Gatula Time does not claim security certifications that have not been independently completed. Formal penetration testing and deployment review remain release gates before production use.