timeware® HRMS  ›  Security & Infrastructure
Briefing for IT departments

Security & Infrastructure.
Built for your IT team's questions.

At timeware UK Ltd, we prioritise security, compliance and data integrity in our cloud-based timeware® HRMS solution. This briefing outlines the technical architecture and controls to address any IT concerns.
Revised 19th August 2026 UK GDPR · ISO 27001:2022 · Cyber Essentials Plus
Hosting regions
Primary
UK South
London
SQL · Blob Storage · Service Bus, every Azure service deployed here
Geo-replication
Disaster recovery
UK West
Cardiff
Active geo-replication and geo-redundant storage, ready to take over
All customer data stored in the UK
No data leaves UK regions
1 · UK data sovereignty

Your data never leaves the UK.

All customer data is stored in the UK.
Primary hosting region: UK South (London); disaster recovery region: UK West (Cardiff).
Every Azure service (SQL, Blob Storage, Service Bus and more) is deployed exclusively in UK regions, ensuring compliance with UK GDPR and the Data Protection Act 2018.
2 · Built on Microsoft Azure

Enterprise controls, on by default.

AES-256
Encryption at rest
AES-256 Transparent Data Encryption (TDE) on all Azure SQL databases.
GEO-REDUNDANT
Geo-redundant storage
Geo-redundant Blob Storage and active geo-replication from UK South to UK West.
WAF + DDOS
Edge protection
Azure Front Door Premium with Web Application Firewall (WAF) and DDoS protection.
TLS 1.2+
Encryption in transit
TLS 1.2 minimum for data in transit; Managed Identity prevents stored credentials between services, with secrets held in Azure Key Vault.
35-DAY RESTORE
Backup & restore
35-day point-in-time restore plus weekly, monthly and yearly backups.
DEFENDER
Threat detection
Microsoft Defender for SQL and Storage for threat detection and malware scanning.
3 · Security enhancements by timeware®

Identity, hardened at every layer.

Single Sign-On via Microsoft Entra ID, with optional OIDC support.
Multi-factor authentication (TOTP, SMS, recovery codes), configurable per tenant.
Account lockout thresholds and password policies: length, complexity, banned words.
SHA-256 hashed API keys and HMAC-SHA256 webhook signing.
Anti-forgery (CSRF) protection and hardened session cookies.
Fine-grained API permission-gating and JWT validation with RSA key rotation.
Short-lived access tokens with refresh-token rotation and replay detection: a replayed token invalidates the whole session.
Per-user, per-endpoint rate limiting and instant account suspension.
Identity & access
Single Sign-On · Microsoft Entra ID
Optional OIDC support
SSO
Multi-factor authentication
TOTP · SMS · recovery codes · configurable per tenant
MFA
Account protection
Lockout thresholds · password length, complexity and banned words
Policy
API & session hardening
SHA-256 hashed keys · HMAC-SHA256 webhooks · CSRF protection · hardened cookies
API
Token validation
Fine-grained permission-gating · JWT validation · RSA key rotation
JWT
Session security
Short-lived access tokens · rotating refresh tokens in HttpOnly secure cookies · replay detection ends the session
Session
4 & 5 · Isolation, audit & retention

Your tenant is yours alone, and everything is on the record.

Tenant data isolation
Tenant A
Own database
Tenant B
Own database
Tenant C
Own database
All domain entities are tenant-scoped, enforced by EF Core query filters.
One tenant per database: each customer has their own dedicated Azure SQL database, never shared.
Azure Elastic Scale acts purely as the routing registry: one tenant key maps to one database.
Automated build pipeline tests ensure no cross-tenant data access.
Audit & retention
JB
Salary updated · £31,200 → £32,500
User, old value, new value and affected columns, all captured
Forensic audit logs capture user actions, old/new values and affected columns.
Hard-delete prevention; soft-deletes purged after retention periods.
Immutable SQL-level audit logs with WORM policy.
Configurable data retention and scheduled purging of soft-deleted data.
6 & 8 · Architecture & technology stack

A modern .NET platform, monitored end to end.

A Blazor WebAssembly client, monolith API and SignalR hub for real-time communication, with dedicated processors for events, batch jobs, media and reports. Health-check endpoints monitor SQL, Service Bus, Redis and Storage for early fault detection.
.NET 10 · latest LTS Blazor WebAssembly Entity Framework Core MassTransit on Azure Service Bus Hangfire & Quartz.NET SignalR · Azure SignalR Service Azure Cache for Redis Sentry error tracking
i
Sentry error tracking stores data in the EU (Frankfurt region). This feature is configurable per tenant, organisations can choose to enable or disable it based on their preference.
Integrations: Suprema biometric devices via G-SDK  ·  BioStar 2 access-control sync  ·  Sage payroll  ·  Developer API, REST + webhooks
9 · Compliance

The checklist your auditors will ask for.

Compliance with UK GDPR, ISO 27001:2022 and Cyber Essentials Plus.
Customer data is stored and processed solely in the UK.
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 TDE).
Access to production data is restricted to authorised timeware UK Ltd personnel and logged.
Configurable retention, 35-day point-in-time restore, long-term backups.
Regular penetration testing and security assessments.
Questions from your IT team?
We are happy to walk your IT department through the architecture in detail, or answer a security questionnaire directly.
Talk to us →
Explore the platform › Migrating from timeware® Professional ›