Chronodesk security

Security and data protection for UK organisations.

Chronodesk is designed to protect operational and client information through encryption, access controls, auditability, backups and flexible deployment conversations. This page summarises the current public security position and the questions to cover during procurement.

  • AES-256 encryption at rest
  • TLS 1.2+ in transit
  • Role-based access control
  • Audit-trail capabilities
  • Automated daily backups
  • GDPR-ready architecture and practices
  • ISO 27001-aligned practices
  • Targets 99.9% uptime (Enterprise)

Alignment is not the same as certification. Chronodesk is not ISO 27001 certified.

Protecting data in transit and at rest

Data at rest is protected using AES-256 encryption, and data in transit uses TLS 1.2 or later.

Encryption is one layer of a wider security model. During procurement, organisations should also review identity, permissions, auditability, backups, support access and the deployment option relevant to their risk profile.

Give people access to the information they need.

Role-based access control allows organisations to separate responsibilities and restrict access to sensitive operational or commercial information. The exact permission model should be demonstrated using representative user roles from your organisation.

Suggested evaluation roles:

  • System administrator
  • Operations or commercial leader
  • Project manager
  • Consultant or engineer
  • Service-desk agent
  • Finance user
  • Client-portal user

Ask Chronodesk to demonstrate the relevant view, edit and export controls for each role.

Maintain a history of important activity.

Chronodesk provides audit-trail capabilities for critical actions. During evaluation, identify which events your organisation must review, retain or export, including authentication, permission changes, record updates and data exports.

Do not state that every field change is audited unless that is confirmed in the current product.

Resilience for operational work.

Chronodesk runs automated daily backups, and the Enterprise plan targets 99.9% uptime.

Before contracting, confirm the details relevant to your organisation:

  • Backup frequency and retention
  • Recovery objectives
  • Service-status communication
  • Incident escalation
  • Planned maintenance communication
  • Support coverage for critical issues

Supporting UK GDPR responsibilities

Chronodesk's architecture and practices are GDPR ready. Software alone cannot make an organisation compliant: the customer remains responsible for how personal data is collected, configured, accessed, retained and used within its environment.

A UK buyer should assess:

  • The roles of controller and processor
  • The Data Processing Agreement
  • Hosting location and international transfers
  • Subprocessors
  • Access controls and administrator responsibilities
  • Retention and deletion processes
  • Data-subject request support
  • Incident-notification arrangements

Discuss the right deployment and data-residency model.

Chronodesk's current security proposition includes a standard cloud, localised instance options and private or segregated deployment options for organisations with additional requirements.

Talk to us about your hosting, data-residency and network requirements. We will explain the available deployment options and document the agreed position before purchase.

What to ask during a software security review

  1. Where will our production data and backups be stored?
  2. Which subprocessors handle our information?
  3. How are user roles and permissions configured?
  4. Which administrative and user actions are audited?
  5. How is customer data exported or deleted?
  6. What are the backup, recovery and availability commitments?
  7. What happens if a security incident affects our data?
  8. Which security documents and test evidence can be reviewed?

Security and data-protection FAQ

Is Chronodesk GDPR compliant?

Chronodesk's architecture and practices are GDPR ready. Compliance depends on the platform, our contractual and operational controls, and the way each customer configures and uses the system — so we recommend reviewing the relevant documents and responsibilities during procurement.

Is Chronodesk ISO 27001 certified?

No. Chronodesk's security practices are aligned with ISO 27001, but Chronodesk is not ISO 27001 certified.

Is data encrypted?

Chronodesk's public security information states that data at rest uses AES-256 encryption and data in transit uses TLS 1.2 or later.

Can Chronodesk be hosted in the UK?

Talk to us about your hosting and data-residency requirements before purchase. We will confirm the available cloud regions, backup locations and commercial terms that apply to your deployment.

Does Chronodesk support SSO?

The Enterprise plan includes SAML SSO and OAuth. We will confirm identity-provider compatibility and configuration with you during evaluation.

Can we review security documents?

Yes. Contact us to request the security documentation available for your evaluation, and we will confirm what can be shared and whether an NDA is required.

Bring your security and procurement questions.

Discuss the information, access, deployment and contractual requirements that matter to your organisation.