Security & trust

TideLine handles schedule data that ends up in delay claims and dispute proceedings. We treat it accordingly — here is exactly how.

Encryption

All data is encrypted in transit with TLS and at rest by our cloud infrastructure provider. Client schedule files are treated as litigation-sensitive throughout their lifecycle.

Data isolation

Every organization's data is isolated with row-level security enforced by the database itself — not by application code. One organization can never read another's projects, entitlements or files, and we test this automatically.

Server-side licensing

Access decisions are made on the server on every request. The application bundle is only delivered after the server verifies a live entitlement from the database — nothing can be unlocked from the browser.

Access control

Organization roles (owner, admin, member) govern who can manage members and billing. Elite Analytics staff actions require staff accounts, a typed reason, and are written to an append-only audit log.

Audit logging

Authentication, entitlement, billing, export and administrative events are recorded in an append-only audit log retained for 24 months.

Data retention & your rights

Cancelled accounts keep their data read-only and exportable for 90 days — it is never silently deleted. You can export your organization's data at any time, and request account deletion with a 30-day recovery window (PIPEDA/GDPR).

Payments

Payment card data never touches our servers. All card handling is performed by Stripe, a PCI DSS Level 1 service provider.

Subprocessors

We use a small set of infrastructure subprocessors for cloud hosting/database, payment processing (Stripe) and transactional email. A current list is available on request.

Questions about security, a security questionnaire, or a data processing agreement? Contact us.