timeware® HRMS  ›  Security & Infrastructure
Briefing for IT departments

Security & Infrastructure.
Built for your IT team's questions.

At timeware UK Ltd, we prioritise security, compliance and data integrity in our cloud-based timeware® HRMS solution. The platform has been developed in-house over more than four years and is still being actively developed, with security controls reviewed as it grows. This briefing outlines the technical architecture and controls to address any IT concerns.
Revised 19th August 2026 UK GDPR · ISO 27001:2022 · Cyber Essentials Plus
Hosting regions
Primary
UK South
London
SQL · Blob Storage · Service Bus, every Azure service deployed here
Geo-replication
→
Disaster recovery
UK West
Cardiff
Active geo-replication and geo-redundant storage, ready to take over
All customer data stored in the UK
No data leaves UK regions
1 · UK data sovereignty

Your data never leaves the UK.

✓
All customer data is stored in the UK.
✓
Primary hosting region: UK South (London); disaster recovery region: UK West (Cardiff).
✓
Every Azure service (SQL, Blob Storage, Service Bus and more) is deployed exclusively in UK regions, ensuring compliance with UK GDPR and the Data Protection Act 2018.
✓
Data stays in the UK while users work anywhere: timeware® HRMS and the mobile apps are localised in fifteen languages, from English, Welsh and French to Arabic, Punjabi and Urdu, with time-zone support from Los Angeles to Sydney.
2 · Built on Microsoft Azure

Enterprise controls, on by default.

AES-256
Encryption at rest
AES-256 Transparent Data Encryption (TDE) on all Azure SQL databases.
GEO-REDUNDANT
Geo-redundant storage
Geo-redundant Blob Storage and active geo-replication from UK South to UK West.
WAF + DDOS
Edge protection
Azure Front Door Premium with Web Application Firewall (WAF) and DDoS protection.
TLS 1.2+
Encryption in transit
TLS 1.2 minimum for data in transit; Managed Identity prevents stored credentials between services, with secrets held in Azure Key Vault.
35-DAY RESTORE
Backup & restore
35-day point-in-time restore plus weekly, monthly and yearly backups. Recovery targets: 1 hour of data, 12 hours to restore if UK South is lost.
DEFENDER
Threat detection
Defender for SQL watches for threats; Defender for Storage virus-scans every upload, holds files back until clean and removes anything malicious.
3 · Security enhancements by timeware®

Identity, hardened at every layer.

✓
Single sign-on with Microsoft Entra ID or Google, chosen per tenant, alongside username and password, in the web app and both mobile apps, timeware® ESS and Fire Marshal.
✓
Each sign-on is single-use, expires after ten minutes and only completes in the browser that started it. Accounts link to the provider’s stable directory ID, not an email address, and invited staff on SSO tenants never set a timeware password.
✓
Multi-factor authentication (TOTP, SMS, recovery codes), configurable per tenant.
✓
Account lockout thresholds and password policies: length, complexity, banned words.
✓
SHA-256 hashed API keys and HMAC-SHA256 webhook signing.
✓
Anti-forgery (CSRF) protection and hardened session cookies.
✓
Fine-grained API permission-gating and JWT validation with RSA key rotation.
✓
Short-lived access tokens with refresh-token rotation and replay detection: a replayed token invalidates the whole session.
✓
Per-user, per-endpoint rate limiting and instant account suspension.
Identity & access
Single sign-on · Microsoft Entra ID or Google
Chosen per tenant · web, ESS and Fire Marshal apps · PKCE · single-use sign-in
SSO
Multi-factor authentication
TOTP · SMS · recovery codes · configurable per tenant
MFA
Account protection
Lockout thresholds · password length, complexity and banned words
Policy
API & session hardening
SHA-256 hashed keys · HMAC-SHA256 webhooks · CSRF protection · hardened cookies
API
Token validation
Fine-grained permission-gating · JWT validation · RSA key rotation
JWT
Session security
Short-lived access tokens · rotating refresh tokens in HttpOnly secure cookies · replay detection ends the session
Session
4 & 5 · Isolation, audit & retention

Your tenant is yours alone, and everything is on the record.

Tenant data isolation
Tenant A
Own database
Tenant B
Own database
Tenant C
Own database
✓
All domain entities are tenant-scoped, enforced by EF Core query filters.
✓
One tenant per database: each customer has their own dedicated Azure SQL database, never shared.
✓
Azure Elastic Scale acts purely as the routing registry: one tenant key maps to one database.
✓
Automated build pipeline tests ensure no cross-tenant data access.
Audit & retention
JB
Salary updated · £31,200 → £32,500
User, old value, new value and affected columns, all captured
✓
Forensic audit logs capture user actions, old/new values and affected columns.
✓
Hard-delete prevention; soft-deletes purged after retention periods.
✓
Immutable SQL-level audit logs with WORM policy.
✓
Configurable data retention and scheduled purging of soft-deleted data.
6 & 8 · Architecture & technology stack

A modern .NET platform, monitored end to end.

A Blazor WebAssembly client, monolith API and SignalR hub for real-time communication, with dedicated processors for events, batch jobs, media and reports. Health-check endpoints monitor SQL, Service Bus, Redis and Storage for early fault detection.
.NET 10 · latest LTS Blazor WebAssembly Entity Framework Core MassTransit on Azure Service Bus Hangfire & Quartz.NET SignalR · Azure SignalR Service Azure Cache for Redis Sentry error tracking
i
Sentry error tracking stores data in the EU (Frankfurt region). This feature is configurable per tenant, organisations can choose to enable or disable it based on their preference.
Integrations: Suprema biometric devices via G-SDK  ·  BioStar 2 access-control sync  ·  Sage payroll  ·  Developer API, REST + webhooks
9 · Compliance

The checklist your auditors will ask for.

✓
Compliance with UK GDPR, ISO 27001:2022 and Cyber Essentials Plus.
✓
Customer data is stored and processed solely in the UK.
✓
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 TDE).
✓
Access to production data is restricted to authorised timeware UK Ltd personnel and logged.
✓
Configurable retention, 35-day point-in-time restore, long-term backups.
✓
Regular penetration testing and security assessments.
10 · AI and your data

AI that proposes, never decides.

AI suggestions on HR records, Reword on text boxes and suggested replies in the Conversation Hub run on OpenAI GPT-6 Luna, deployed in Microsoft Azure UK South under Microsoft’s enterprise data terms.
✓
Prompts and outputs are never used to train models and are not shared with OpenAI.
✓
One request, no tools: the model cannot browse, call other systems or change data. Anything but a complete, valid answer is discarded.
✓
Permissions are checked before the record is read and again before the answer is shown.
✓
Tenant controls: a switch for each AI feature (assistant, reply drafts, Suggest, Reword and Reword on statements), and health records kept out unless you opt them in.
✓
Daily limits per user and per tenant. Not available to employee self-service logins.
✓
Logs record timing and token counts only, never the record or the answer.
✓
Social feed posts and library pictures are checked by Azure AI Content Safety before they go out; the author confirms anything flagged.
Service levels
99.5% monthly availability target, 24-hour monitoring, P1 response within 1 hour, and recovery within 12 hours if UK South is lost.
Service level targets ›
Questions from your IT team?
We are happy to walk your IT department through the architecture in detail, or answer a security questionnaire directly.
Talk to us →
Explore the platform › Migrating from timeware® Professional ›