Security & compliance

Built for teams that need trust before they track time.

Quiet, honest infrastructure choices — so the time you track, the clients you serve and the money you bill stay protected.

Privacy by design

We collect the minimum we need to run the product. The product and legal terms are designed around Quebec Law 25, Canada's PIPEDA and core GDPR expectations such as access, correction, deletion and portability.

Encrypted in transit and at rest

All traffic is TLS 1.3. Database storage is encrypted at rest on Supabase's hardened Postgres infrastructure. Backups inherit the same protections.

Secure authentication

Sign in with Google or Slack OAuth, magic link, or email + password. Sessions are isolated per device. Account-level role-based access for teams.

PCI-secure payments

Stripe handles every subscription transaction. Militime never sees or stores your card data; tokens only.

Hardened infrastructure

Hosted on Vercel + Supabase. DDoS protection at the edge, automatic patching, sandboxed compute. We do not run unmanaged servers.

Full data portability

Every project, invoice and time entry exports as CSV or PDF on demand. Delete your account anytime — we honor the request end-to-end.

Compliance

Privacy commitments we design around

Quebec Law 25 (Loi 25)

Privacy officer designated. Consent collection, breach notification and right of access aligned with the modernized Act.

Canada — PIPEDA

Product and policy choices are designed around Canadian privacy principles for accountability, consent, safeguards and access.

European Union — GDPR

Data minimization, lawful basis, erasure and portability are treated as product requirements for EU residents.

Stripe — PCI DSS

Card data handled exclusively by Stripe's PCI-Level-1 certified infrastructure.

Security questions or a vulnerability to report? Reach our privacy officer.

Run your billable work on calm, secure infrastructure.

Start a 14-day free trial — cancel anytime.