ClockDocCreate an account

Security

Last updated 8 September 2026

ClockDoc holds what your team worked on and what you charge for it, which is worth protecting. This page says what is actually in place, in specifics rather than adjectives.

Passwords

  • Stored only as a salted hash. They cannot be read back, by us or by anyone with database access.
  • Never written to logs, and never sent by email.
  • You can sign in with Google or Microsoft instead, in which case ClockDoc never handles a password at all.
  • Changing or resetting a password revokes every existing session, on every device.

Sessions

  • A short-lived access token does the work, paired with a refresh token in a cookie marked HttpOnly, Secure and SameSite=Lax. Browser scripts cannot read it, it is only sent over HTTPS, and it is not sent on cross-site requests.
  • Refresh tokens rotate on use. If an already-used token is presented again — the signature of a stolen token — that whole chain of sessions is revoked rather than renewed.
  • Signing out ends that session without disturbing your other devices.
  • Expired tokens are deleted by a scheduled job rather than left to accumulate.

Access control

  • Every request is authorised on the server against your role and your membership of the specific project. The interface hiding a button is never the thing that enforces it.
  • Data is scoped per organisation. Belonging to one organisation gives you no access to another's, including where the same person belongs to both.
  • Rates, budgets and commission figures are stripped from responses for anyone without permission to see them, rather than hidden in the interface.
  • Significant changes are recorded in an audit log an administrator can read.

In transit and at rest

  • All traffic is served over HTTPS.
  • The database is hosted in the European Union, with access restricted to the application.
  • The database is backed up daily.

On your phone

The installed app caches responses so your recent week stays readable offline. That cache never holds credentials, and it is cleared at every session boundary — signing out, switching organisation, or signing in as someone else — so a shared device does not serve one person's data to the next.

What we do not do

  • No analytics, advertising or third-party tracking scripts.
  • No selling or sharing of your data. See the privacy page.
  • No plain-text passwords, anywhere, ever.

Reporting a vulnerability

If you find a security problem, email [email protected] with enough detail to reproduce it. We will confirm we received it, keep you updated while it is being fixed, and credit you if you would like that.

Please give us a reasonable chance to fix it before disclosing it publicly, and while testing do not access other people's data, degrade the service for others, or run automated scans that amount to a denial of service. Report it in good faith and we will treat it in good faith.

Honest limits

ClockDoc is built by a small team and is free. It has not been through an external security audit or a SOC 2 assessment, and we would rather say so than imply otherwise. If your organisation needs that level of assurance, talk to us at [email protected] before you rely on it.

HomeWhat's newPrivacyTermsSecurityContact

© 2026 Grasp