Security
Built to measure your work, not to expose it.
DevClocked handles the record of how you build software. That data is protected with encryption in transit and at rest, strict per-account isolation, and tracking that never touches your source code.
Data protection
How we protect your data.
Protection is layered into every path your data takes, from the tracker on your machine to the dashboard in your browser.
Encrypted in transit
Every connection between your trackers, your browser, and DevClocked is encrypted with TLS. No tracking data travels in the clear.
Encrypted at rest
Your data is encrypted at rest. OAuth tokens for connected services like GitHub get an additional layer of encryption before they are ever stored.
Strict tenant isolation
Row-level isolation is enforced in the database itself, not just in application code. Your account can only ever read and write its own data.
Scoped, revocable API keys
Tracker API keys are stored as one-way hashes and shown to you exactly once. Each key carries limited scopes, and revoking one takes effect immediately.
Payments handled by Stripe
All billing runs through Stripe, a certified PCI Service Provider. Your card details go directly to Stripe and never touch DevClocked systems.
Your own audit trail
Security-relevant account events, like key creation, connections, and deletions, are recorded and visible to you inside the app.
Privacy-first tracking
The strongest protection is data we never collect.
DevClocked records operational metadata about your sessions, never the work itself. There is no surveillance layer to secure because it does not exist.
No screenshots
DevClocked never captures your screen. Not on an interval, not on demand, not for managers.
No keystroke logging
No keystroke counts, no keystroke patterns, no input recording of any kind.
No file contents
Source code and file contents stay on your machine. Only session metadata, like durations, repo names, and languages, ever syncs.
No camera or mic
No webcam snapshots, no microphone access, no screen recording. Ever.
Data control
Your data stays yours.
You can inspect, export, and permanently delete everything DevClocked holds about you, without a support ticket.
Export everything
Download your complete history as a JSON bundle at any time. No lock-in, no export paywall.
Delete what you want
Remove individual sessions or reset your tracked data whenever you choose. Deleted means deleted, not archived.
Delete your account
Account deletion is self-serve and permanent. When you delete your account, your data is removed with it.
Responsible disclosure
Found a vulnerability? Tell us.
We welcome good-faith security research and will work with you to verify and fix real issues quickly.
Report a vulnerability
Email us directly. We read every report.
Include what you found, the steps to reproduce it, and the impact you believe it has. Please give us a reasonable window to fix the issue before any public disclosure.
In return, we ask that you avoid accessing data that is not yours, degrading the service, or running automated scans against production. Good-faith research conducted this way will not be met with legal action.
A machine-readable policy lives at /.well-known/security.txt.