Security & data protection
Your payroll data, isolated to the row.
Timesheets and overtime are pay data — some of the most sensitive information you hold. In A Tick protects it with tenant isolation enforced by the database, zero-trust checks on every request, encryption in transit and at rest, and a full audit trail. Same protection on every plan — security isn't a premium tier.
How isolation works
One database, walled off row by row.
Multi-tenant apps usually keep customers apart with application code that remembers to filter by account. We don't rely on remembering. Isolation is pushed down into the database itself.
Row-level security, not a WHERE clause you hope is there
Every request runs in the context of a single organisation, and the database applies a row-level security policy to every read and write. Even if application code forgot a filter — or a bug tried to over-fetch — the database returns nothing that doesn't belong to your organisation.
Zero-trust on every request
The browser is never the source of truth. Every action is re-checked on the server against who you are and what you're allowed to do — so a tampered request can't talk the backend into doing something it shouldn't.
- Server re-validates every action independently
- Credentials never travel in URLs or logs
- Sessions issued and checked server-side
- Defence in depth — app checks and database policy
What ships on every plan
Security built in, not sold as an upgrade.
The same protections apply whether you're one team or one thousand. There is no security tier to buy.
Tenant isolation, enforced by the database
Row-level security makes your data invisible to every other organisation — not by convention, but as a constraint the database applies to every query.
Zero-trust, end to end
Every action is re-validated on the server before it runs. No client is trusted, no shortcut is taken — the browser can never talk the backend into skipping a check.
Encrypted in transit and at rest
Your data is encrypted over TLS on the wire and encrypted at rest in the database, with credentials kept out of URLs and logs.
Audited by default
Approvals, rejections, delegations and admin access are all recorded and visible to your admins. Payroll integrity by default, not by request.
Modern authentication
Sign in with email and password or a passwordless magic link, with sessions issued and re-validated server-side. Passkeys and single sign-on (SSO) for higher-tier plans are on our roadmap.
AI you stay in control of
AI (a Premium feature) only reads your data to advise — suggestions, summaries and anomaly flags. It never touches your pay rules, and you can switch it off at any time.
Hosting & compliance
Honest about where we are.
We'd rather tell you exactly what's true today than claim certifications we haven't earned.
Hosted in Singapore
Your data is hosted in Singapore today. Per-region data-residency options — keeping data in a specific jurisdiction — are on our roadmap.
Certification: on the roadmap
In A Tick is in early access. We're building toward formal certification rather than claiming badges we haven't earned. Ask us about our current practices any time.
Trust centre coming soon
A dedicated trust centre — with our data-protection documentation and answers to due-diligence questions — is on the way. Get in touch in the meantime.
Security FAQ
The questions your security review will ask.
Straight answers to the data-protection questions teams raise before they move their timesheets over.
- How is my organisation's data kept separate from other customers?
- Every organisation's data is isolated by row-level security in the database. Each request runs in the context of one tenant, and the database itself filters every query to that tenant — so a mistake in application code cannot return another organisation's rows. Isolation is a constraint the database enforces, not a convention the app is trusted to follow.
- Is my data encrypted?
- Yes. Data is encrypted in transit over TLS between your browser and our servers, and encrypted at rest in the database. Credentials are kept out of URLs and application logs by design.
- How are payments and card details handled?
- Payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider. Card details are entered directly with Stripe and are never stored on In A Tick's servers — we only keep a reference to your subscription, never your full card number.
- Where is my data hosted?
- All data is currently hosted in Singapore. Per-region data-residency options are on our roadmap for organisations that need data kept in a specific jurisdiction.
- Do you hold SOC 2 or ISO 27001 certification?
- Not yet. In A Tick is an early-access product, and we are building toward formal certification rather than claiming badges we have not earned. We are happy to walk prospective customers through our current security architecture and practices in the meantime.
- How do people sign in, and do you support SSO?
- Today your team signs in with email and a password or a passwordless magic link, and every session is issued and re-validated on the server. Passkeys and single sign-on (SSO) for higher-tier plans are on our roadmap.
- How do you use AI with my data?
- AI features are available on Premium plans and are strictly advisory: they read your timesheet data to suggest entries, summarise a week in plain language and flag anomalies before payroll. They never change your overtime rules or pay calculations — that engine stays fully deterministic — and you can turn AI off whenever you want.
- How can I get a DPA or your security documentation?
- A full trust centre with our data-protection documentation is on the way. Until it lands, get in touch and we will share what we can about our security practices to support your due diligence.
Security you don't have to think about.
Set up your organisation and see how your data is isolated from the first click — free while we're in early access.