Security
Thyme — Security
Last updated 10 June 2026
On this page
Thyme is built to handle sensitive commercial data — your proposals, projects, billings and cashflow — so security and privacy are foundational to how we design the platform, not an afterthought.
Thyme is in active development ahead of launch. This page describes the security posture and practices we are building into the platform. We will keep it current as the product and our controls mature, and we are happy to discuss specifics with prospective customers during onboarding.
Our approach
We design Thyme around a few principles: protect data in transit and at rest, give each customer strong isolation, grant access on a least-privilege and need-to-know basis, and build security into our development process rather than bolting it on. We use recognised frameworks — including the Australian Privacy Principles and established security standards such as ISO/IEC 27001 and SOC 2 — as reference points for the controls we are putting in place.
Hosting and infrastructure
Thyme runs on reputable, enterprise-grade cloud infrastructure operated by a major provider with strong physical and operational security. We design for customer data to be hosted in Australia. Our infrastructure is managed, monitored and kept up to date with security patches, and production systems are separated from development and testing environments.
Encryption
We encrypt data in transit using current TLS standards, and data at rest using strong, industry-standard encryption (such as AES-256). Secrets and keys are managed using dedicated key-management services rather than stored in application code.
Access control and authentication
Access to the Service is governed by role- and permission-based controls, so each user sees only what their role allows. We support strong authentication, including single sign-on and multi-factor authentication where available. Internal access to production systems and customer data is restricted to authorised personnel on a need-to-know basis, is logged, and is reviewed.
Tenant isolation
Each customer's data is logically separated, so one customer cannot access another customer's data. Access controls are enforced at the application and data layers.
Application and network security
We follow secure development practices, including code review, testing, and dependency management, and we design against common web application risks (such as the OWASP Top 10). Network controls, firewalls and segmentation are used to limit exposure of production systems.
Monitoring, logging and resilience
We monitor the Service for availability and security anomalies, and maintain audit and system logs. We design for resilience with regular backups, defined recovery objectives, and redundancy, which also underpins the uptime commitments in our Service Level Agreement.
Vendors and sub-processors
Where we use third-party providers to deliver the Service (for example, hosting, email, analytics, payments and support), we select reputable providers and require them to protect data appropriately. We handle personal information in accordance with our Privacy Policy.
Your data is yours
You own your data. We use it to provide and improve the Service as described in our Terms of Service and Privacy Policy, and any benchmarking or model-development use is carried out only on aggregated, de-identified data that does not identify you, any individual, or any single customer.
Incident response
We maintain processes to detect, investigate and respond to security incidents. If a data breach affects your personal information, we will notify affected customers and act in accordance with our legal obligations, including the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
Shared responsibility
Security is a partnership. You can help keep your account safe by using strong, unique credentials, enabling multi-factor authentication, managing your own users and their permissions carefully, and ensuring you have the right to load the data you put into Thyme.
Contact
To report a security concern or ask a security question, contact security@truethyme.com.