timeware® HRMS › Security & Infrastructure
Briefing for IT departments
Security & Infrastructure.
Built for your IT team's questions.
At timeware UK Ltd, we prioritise security, compliance and data integrity in our cloud-based timeware® HRMS solution. This briefing outlines the technical architecture and controls to address any IT concerns.
Revised 19th August 2026
UK GDPR · ISO 27001:2022 · Cyber Essentials Plus
1 · UK data sovereignty
Your data never leaves the UK.
✓
All customer data is stored in the UK.
✓
Primary hosting region: UK South (London); disaster recovery region: UK West (Cardiff).
✓
Every Azure service (SQL, Blob Storage, Service Bus and more) is deployed exclusively in UK regions, ensuring compliance with UK GDPR and the Data Protection Act 2018.
2 · Built on Microsoft Azure
Enterprise controls, on by default.
AES-256
Encryption at rest
AES-256 Transparent Data Encryption (TDE) on all Azure SQL databases.
GEO-REDUNDANT
Geo-redundant storage
Geo-redundant Blob Storage and active geo-replication from UK South to UK West.
WAF + DDOS
Edge protection
Azure Front Door Premium with Web Application Firewall (WAF) and DDoS protection.
TLS 1.2+
Encryption in transit
TLS 1.2 minimum for data in transit; Managed Identity prevents stored credentials between services, with secrets held in Azure Key Vault.
35-DAY RESTORE
Backup & restore
35-day point-in-time restore plus weekly, monthly and yearly backups.
DEFENDER
Threat detection
Microsoft Defender for SQL and Storage for threat detection and malware scanning.
3 · Security enhancements by timeware®
Identity, hardened at every layer.
✓
Single Sign-On via Microsoft Entra ID, with optional OIDC support.
✓
Multi-factor authentication (TOTP, SMS, recovery codes), configurable per tenant.
✓
Account lockout thresholds and password policies: length, complexity, banned words.
✓
SHA-256 hashed API keys and HMAC-SHA256 webhook signing.
✓
Anti-forgery (CSRF) protection and hardened session cookies.
✓
Fine-grained API permission-gating and JWT validation with RSA key rotation.
✓
Short-lived access tokens with refresh-token rotation and replay detection: a replayed token invalidates the whole session.
✓
Per-user, per-endpoint rate limiting and instant account suspension.
4 & 5 · Isolation, audit & retention
Your tenant is yours alone, and everything is on the record.
Tenant data isolation
Tenant A
Own database
Tenant B
Own database
Tenant C
Own database
✓
All domain entities are tenant-scoped, enforced by EF Core query filters.
✓
One tenant per database: each customer has their own dedicated Azure SQL database, never shared.
✓
Azure Elastic Scale acts purely as the routing registry: one tenant key maps to one database.
✓
Automated build pipeline tests ensure no cross-tenant data access.
Audit & retention
JB
Salary updated · £31,200 → £32,500
User, old value, new value and affected columns, all captured
✓
Forensic audit logs capture user actions, old/new values and affected columns.
✓
Hard-delete prevention; soft-deletes purged after retention periods.
✓
Immutable SQL-level audit logs with WORM policy.
✓
Configurable data retention and scheduled purging of soft-deleted data.
6 & 8 · Architecture & technology stack
A modern .NET platform, monitored end to end.
A Blazor WebAssembly client, monolith API and SignalR hub for real-time communication, with dedicated processors for events, batch jobs, media and reports. Health-check endpoints monitor SQL, Service Bus, Redis and Storage for early fault detection.
.NET 10 · latest LTS
Blazor WebAssembly
Entity Framework Core
MassTransit on Azure Service Bus
Hangfire & Quartz.NET
SignalR · Azure SignalR Service
Azure Cache for Redis
Sentry error tracking
i
Sentry error tracking stores data in the EU (Frankfurt region). This feature is configurable per tenant, organisations can choose to enable or disable it based on their preference.
Integrations: Suprema biometric devices via G-SDK · BioStar 2 access-control sync · Sage payroll · Developer API, REST + webhooks
Questions from your IT team?
We are happy to walk your IT department through the architecture in detail, or answer a security questionnaire directly.