> ## Documentation Index
> Fetch the complete documentation index at: https://docs.shiftsheet.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Trust

> How Shiftsheet secures your data, infrastructure compliance, and operational practices.

Shiftsheet combines a highly audited cloud foundation with purpose-built controls for Australian workforce data. Our design prioritises compliance, minimal data exposure, and ease of secure use — helping teams reduce risk compared to spreadsheets or unsecured tools.

## Infrastructure & Certifications

Shiftsheet runs on Vultr, a high-performance cloud platform known for reliable, secure infrastructure, including options for Australian data residency. Their enterprise-grade certifications include:

* **SOC 2 Type II** (with HIPAA alignment)
* **ISO/IEC 27001:2022** (Information Security Management)
* **ISO 27017 & 27018** (Cloud security & PII protection)
* GDPR-compliant practices & DDoS protection

Internally, we align with the core requirements of these standards and are progressing toward our own formal ISMS accreditation.

## Data Security & Privacy

* **Encryption:** Data is encrypted in transit (TLS 1.2+) and at rest.
* **Access Controls:** Role-based access (Employee / Manager / Admin) enforcing least-privilege principles. MFA (email OTP) on login.
* **Australian Focus:** Built for Fair Work Act compliance, securing timesheets, leave balances, and payroll exports.
* **Data Minimisation:** We collect and process only the employee and timesheet data strictly necessary.

## Operational Security

* **Authentication:** Every login is verified with a one-time email OTP. New companies can sign up directly, but joining an *existing* company as an employee, manager, or admin is invite-only via a secure emailed token — no one can join another company's workspace without an invitation.
* **Auditing:** Timesheet approvals, leave requests, and system changes are securely logged for accountability.
* **Resilience:** Automated backups and redundant infrastructure for robust business continuity.
* **Mobile Access:** Secure browser-based access (no dedicated app required), keeping local devices safe.

## Customer Best Practices

Security is a shared responsibility. We recommend customers:

1. Use strong, unique email passwords and enable all available verification steps.
2. Review and approve timesheets and leave requests promptly.
3. Export sensitive reports securely and manage local copies responsibly.
4. Control user invitations, roles, and company settings diligently.

## Questions or Vulnerability Reporting

We are happy to share detailed information about our current security practices or support your due diligence process. If you believe you have found a security vulnerability in Shiftsheet, please do not disclose it publicly. Contact us at [support@ntime.au](mailto:support@ntime.au).
