Security at HourChimp

How we protect your data - and your clients' data.

At HourChimp, we take your data seriously. Our aim is simple: give you and your clients a secure, transparent place to track retainer hours - without cutting corners on how that data is protected.

Encryption

• In transit: All traffic is encrypted via TLS/HTTPS, including the app, API requests, and shared client portal links.

• At rest: All data is stored in Neon Postgres, encrypted at rest to AES-256-equivalent standards.

Authentication

We use email magic links and OAuth (via NextAuth.js/Auth.js) for login. We never store plaintext or hashed passwords. That removes an entire category of risk - password leaks, reuse attacks, and credential stuffing simply don't apply to HourChimp accounts.

Client Portal

Your clients view their retainer balance through a unique, cryptographically random UUID link - not a login. Links are read-only and not sequential or predictable, so there's no way to guess or "walk" from one client's link to another's. You can revoke or regenerate any link at any time.

Payments

All billing runs through Stripe Checkout and the Stripe Customer Portal. Card numbers and billing details are entered directly on Stripe's PCI-DSS Level 1 certified infrastructure - they never touch our servers. We store only a Stripe Customer ID to link your account to your subscription.

Hosting & Backups

HourChimp runs on Vercel (serverless/edge) with Neon Postgres as our managed database. Both providers maintain automated, encrypted backups and target enterprise-grade uptime (99.9%+).

Our Vendors

ProviderRole
VercelHosting
NeonDatabase
StripePayments (PCI-DSS Level 1)
ResendTransactional email
SentryError monitoring

If you're evaluating HourChimp for your team and have a security question not covered here, reach out - we're happy to help.
security@hourchimp.com

Product

FeaturesPricingIntegrations

© 2026 HourChimp. All rights reserved.