Trust Center

    Tim handles your work. We take that seriously. This page is the authoritative source for our security posture, compliance status, and the controls we put in place — kept current alongside the codebase, not in a dusty PDF.

    Last reviewed 2026-05-04.

    Encryption

    Live
    • Per-workspace Fernet envelope encryption for memory + transcripts
    • TLS 1.2+ end-to-end on every API edge
    • Workspace KEK rotation supported (90-day max key age)
    • ACS Calling audio handled in MS-eligible regions only

    SOC 2 Type II

    In progress
    • Type I report under finalization
    • Type II observation window underway
    • Audit-export endpoints + 7-year retention live
    • Available under NDA — request below

    GDPR

    Live
    • Article 28 processor obligations honored
    • Sub-processor list + DPA template available
    • EU residency mode (microsoft_only) supported per workspace
    • Subject access + erasure flows automated

    ISO 27001

    Roadmap
    • Targeting Q4 2026 certification
    • Controls already aligned via SOC 2 work
    • Will publish certificate when issued

    Documents

    The following are available under NDA. Request via the form at the bottom of the page (or email trust@gettim.co).

    • SOC 2 Type I reportAvailable now
    • SOC 2 Type II reportAvailable Q3 2026
    • Penetration test report (latest)Available now
    • DPA template (Article 28)Self-serve PDF
    • Sub-processor listSee below
    • Security whitepaperSelf-serve PDF
    • GDPR Records of Processing Activity (RoPA)On request
    • Insurance certificate (cyber + E&O)On request

    Sub-processors

    Tim relies on the following sub-processors. Notice of changes is given 30 days in advance via the changelog at status.gettim.co.

    ProviderPurposeRegionData class
    Microsoft AzureCompute, storage, ACS Communications, Speech, OpenAIEU + USAll customer data
    Google AI Studio / Vertex AILLM inference (Gemini)US (Vertex EU optional)Prompts + completions
    AnthropicLLM inference (Claude)USPrompts + completions
    StripeBilling + Issuing (commerce v1)US/EUPayment metadata
    PipedreamOAuth rail for 600+ third-party APIsUSOAuth tokens
    SentryError monitoringUSStack traces (PII-scrubbed)
    PostHogProduct analyticsEUAnonymized events
    SEC EDGAR (public)G12 funding + exec-change signals (Form D, 8-K)USPublic corporate filings
    Google News RSS (public)G12 news signal keyword sweepsGlobalPublic news articles
    Hacker News API (public)G12 tech mention + Show HN signalsUSPublic posts
    Greenhouse / Lever public boardsG12 hiring-burst signal detectionUSPublic job postings
    WikidataG12 corporate metadata enrichmentGlobalPublic structured data
    Companies House (UK)G12 UK funding + officer-change signalsUKPublic corporate filings
    HubSpot (workspace-connected)G12 CRM sync (bi-directional) — contact + activity write; contact pull into ProspectsUS/EU (workspace choice)Prospect contact + activity log
    Pipedrive (workspace-connected)G12 CRM sync (bi-directional) — person + activity + deal write; person pull into ProspectsEUProspect contact + activity log
    LinkedIn (workspace user OAuth)G12 engagement signals + DM + post; workspace user's own account onlyGlobalWorkspace user's LinkedIn activity
    TechCrunch RSSG12 funding + launch news firehoseUS/GlobalPublic news article metadata
    Reuters RSSG12 corporate news firehoseGlobalPublic news article metadata
    Bloomberg RSSG12 markets + corporate news firehoseGlobalPublic news article metadata
    Yahoo Finance RSSG12 finance news firehoseUS/GlobalPublic news article metadata
    Bing NewsG12 supplemental news search (Azure free tier)GlobalPublic news article metadata
    Crunchbase Pro (BYO key)G12 premium funding depth — opt-in per workspace, key encrypted on workspace rowUSPublic corporate funding records
    Apollo (BYO key)G12 prospect enrichment — opt-in per workspaceUSProspect enrichment metadata
    Clay (BYO key)G12 prospect enrichment — opt-in per workspaceUSProspect enrichment metadata
    Lusha (BYO key)G12 prospect enrichment — opt-in per workspaceUS/EUProspect enrichment metadata
    RB2B (BYO key)G12 website-visitor identification — opt-in per workspaceUSVisitor identification signals

    Vulnerability disclosure

    If you've found a security issue, please report it to security@gettim.co. PGP key on request. We respond within 24 hours and aim to ship a fix within 90 days for all confirmed issues. Public acknowledgment + bounty are available — see our full security policy.

    • Initial response: ≤ 24 hours
    • Triage decision: ≤ 5 business days
    • Fix target: 90 days for critical/high; 180 days for medium
    • Coordinated disclosure: standard 90-day window

    System status

    Live uptime + incident history.

    status.gettim.co

    Request documents

    Send a one-line email describing what you need (SOC 2 letter, pen-test report, DPA) plus the company name to trust@gettim.co. Most documents land in your inbox within one business day.

    Questions about this page or our security posture? Contact us.