Security

    Built to measure your work, not to expose it.

    DevClocked handles the record of how you build software. That data is protected with encryption in transit and at rest, strict per-account isolation, and tracking that never touches your source code.

    Data protection

    How we protect your data.

    Protection is layered into every path your data takes, from the tracker on your machine to the dashboard in your browser.

    Encrypted in transit

    Every connection between your trackers, your browser, and DevClocked is encrypted with TLS. No tracking data travels in the clear.

    Encrypted at rest

    Your data is encrypted at rest. OAuth tokens for connected services like GitHub get an additional layer of encryption before they are ever stored.

    Strict tenant isolation

    Row-level isolation is enforced in the database itself, not just in application code. Your account can only ever read and write its own data.

    Scoped, revocable API keys

    Tracker API keys are stored as one-way hashes and shown to you exactly once. Each key carries limited scopes, and revoking one takes effect immediately.

    Payments handled by Stripe

    All billing runs through Stripe, a certified PCI Service Provider. Your card details go directly to Stripe and never touch DevClocked systems.

    Your own audit trail

    Security-relevant account events, like key creation, connections, and deletions, are recorded and visible to you inside the app.

    Privacy-first tracking

    The strongest protection is data we never collect.

    DevClocked records operational metadata about your sessions, never the work itself. There is no surveillance layer to secure because it does not exist.

    No screenshots

    DevClocked never captures your screen. Not on an interval, not on demand, not for managers.

    No keystroke logging

    No keystroke counts, no keystroke patterns, no input recording of any kind.

    No file contents

    Source code and file contents stay on your machine. Only session metadata, like durations, repo names, and languages, ever syncs.

    No camera or mic

    No webcam snapshots, no microphone access, no screen recording. Ever.

    Data control

    Your data stays yours.

    You can inspect, export, and permanently delete everything DevClocked holds about you, without a support ticket.

    Export everything

    Download your complete history as a JSON bundle at any time. No lock-in, no export paywall.

    Delete what you want

    Remove individual sessions or reset your tracked data whenever you choose. Deleted means deleted, not archived.

    Delete your account

    Account deletion is self-serve and permanent. When you delete your account, your data is removed with it.

    Responsible disclosure

    Found a vulnerability? Tell us.

    We welcome good-faith security research and will work with you to verify and fix real issues quickly.

    Report a vulnerability

    Email us directly. We read every report.

    security@devclocked.com

    Include what you found, the steps to reproduce it, and the impact you believe it has. Please give us a reasonable window to fix the issue before any public disclosure.

    In return, we ask that you avoid accessing data that is not yours, degrading the service, or running automated scans against production. Good-faith research conducted this way will not be met with legal action.

    A machine-readable policy lives at /.well-known/security.txt.

    Measured at the source. Protected at every layer.

    Encryption in transit and at rest, strict per-account isolation, and tracking that never touches your code.

    Book demo