Source
Security / trust page — Timely
Checked for Timely on 30 Sep 2026
- Page
- https://www.timely.com/security/
- Checked
- 30 Sep 2026, 12:05 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:317a178beeb1e44a0154aad8181ae6432e72390e29b5cd0927fe0a5e4e214138
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
ISO 27001 Report an error
“Timely is ISO 27001:2022 certified, meaning our information security management system has been independently audited against the most widely recognised global standard for data security.”
-
DPA GDPR Report an error
“Our Data Processing Agreement (DPA) clearly sets out our obligations under GDPR and other applicable privacy laws.”
-
Provider Report an error
“Timely is built on Amazon Web Services (AWS), using EU-based data centres with high levels of physical and environmental protection.”
-
Data residency Report an error
“EU-based data residency (your data stays in-region)”
-
Isolation Report an error
“Isolated environments per customer account”
-
Backups Report an error
“Automated encrypted backups with regular integrity checks”
-
Encryption in transit Report an error
“Data in transit: All traffic between client devices and Timely services is encrypted using TLS 1.2 or higher. This applies to web traffic, API calls, and third-party integrations.”
-
Encryption at rest Report an error
“Data at rest: All stored data, including databases and file storage, is encrypted using AES-256, one of the most secure encryption standards currently available.”
-
Key management Report an error
“Timely uses AWS Key Management Service (KMS) to manage encryption keys securely, with automated key rotation, granular access policies and full audit logging.”
-
Access controls Report an error
“Access to customer data is strictly controlled using a combination of role-based access controls (RBAC), multi-factor authentication (MFA), and least-privilege principles.”
-
SSO internal Report an error
“Internally, access is managed through identity providers and enforced via single sign-on (SSO), with centralised audit logging.”
-
No standing access Report an error
“Zero standing access to production systems”
-
Vulnerability scanning Report an error
“Weekly vulnerability scanning of infrastructure and dependencies”
-
Secure development Report an error
“We use static code analysis, dependency checking, and container security tools to prevent vulnerabilities from entering the codebase.”
-
Incident response Report an error
“Timely maintains a structured incident response plan covering detection, triage, containment, resolution, and post-incident analysis. This plan is tested regularly through simulations and tabletop exercises.”
-
Breach notification Report an error
“Customers are notified promptly in the event of any breach that affects their data, and post-incident reviews are conducted to improve future detection and response.”
-
Monitoring Report an error
“Real-time infrastructure monitoring and alerting Security information and event management (SIEM) Behavioural analytics to detect anomalies Incident triage workflows and escalation protocols 24/7 alert coverage with on-call engineering rotation”
-
Ownership Report an error
“You retain full ownership and control over your data in Timely. We only process your data to provide and improve the service, and we never sell, share or use it for advertising.”
-
Access export delete Report an error
“Customers can access, export or delete their data at any time through the Timely interface.”
-
Entity Report an error
“Timely AS Hausmannsgate 16, 0182 Oslo, Norway”
-
Governance Report an error
“Quarterly risk assessments and internal audits Annual ISO 27001 surveillance audits Mandatory employee security training and onboarding Ongoing policy reviews and procedural updates”
9 facts read from this page are not shown because they could not be confirmed on the page as captured.