Chronodesk security
Security and data protection for UK organisations.
Chronodesk is designed to protect operational and client information through encryption, access controls, auditability, backups and flexible deployment conversations. This page summarises the current public security position and the questions to cover during procurement.
- ✓ AES-256 encryption at rest
- ✓ TLS 1.2+ in transit
- ✓ Role-based access control
- ✓ Audit-trail capabilities
- ✓ Automated daily backups
- ✓ GDPR-ready architecture and practices
- ✓ ISO 27001-aligned practices
- ✓ 99.9% uptime SLA (Enterprise)
Alignment is not the same as certification. Chronodesk should only be described as certified if formal certification is obtained and current.
Protecting data in transit and at rest
Chronodesk's current public security information states that data at rest is protected using AES-256 encryption and data in transit uses TLS 1.2 or later.
Encryption is one layer of a wider security model. During procurement, organisations should also review identity, permissions, auditability, backups, support access and the deployment option relevant to their risk profile.
Give people access to the information they need.
Role-based access control allows organisations to separate responsibilities and restrict access to sensitive operational or commercial information. The exact permission model should be demonstrated using representative user roles from your organisation.
Suggested evaluation roles:
- System administrator
- Operations or commercial leader
- Project manager
- Consultant or engineer
- Service-desk agent
- Finance user
- Client-portal user
Ask Chronodesk to demonstrate the relevant view, edit and export controls for each role.
Maintain a history of important activity.
Chronodesk provides audit-trail capabilities for critical actions. During evaluation, identify which events your organisation must review, retain or export, including authentication, permission changes, record updates and data exports.
Do not state that every field change is audited unless that is confirmed in the current product.
Resilience for operational work.
The current public security page states that Chronodesk uses automated daily backups. The applicable Enterprise proposition includes a 99.9% uptime SLA.
Before contracting, confirm the details relevant to your organisation:
- Backup frequency and retention
- Recovery objectives
- Service-status communication
- Incident escalation
- Planned maintenance communication
- Support coverage for critical issues
Supporting UK GDPR responsibilities
Chronodesk's public position is that its architecture and practices are GDPR ready. Software alone cannot make an organisation compliant: the customer remains responsible for how personal data is collected, configured, accessed, retained and used within its environment.
A UK buyer should assess:
- The roles of controller and processor
- The Data Processing Agreement
- Hosting location and international transfers
- Subprocessors
- Access controls and administrator responsibilities
- Retention and deletion processes
- Data-subject request support
- Incident-notification arrangements
Discuss the right deployment and data-residency model.
Chronodesk's current security proposition includes a standard cloud, localised instance options and private or segregated deployment options for organisations with additional requirements.
Talk to us about your hosting, data-residency and network requirements. We will explain the available deployment options and document the agreed position before purchase.
What to ask during a software security review
- Where will our production data and backups be stored?
- Which subprocessors handle our information?
- How are user roles and permissions configured?
- Which administrative and user actions are audited?
- How is customer data exported or deleted?
- What are the backup, recovery and availability commitments?
- What happens if a security incident affects our data?
- Which security documents and test evidence can be reviewed?
Security and data-protection FAQ
Is Chronodesk GDPR compliant?
Chronodesk describes its architecture and practices as GDPR ready. Compliance depends on the platform, the supplier's contractual and operational controls and the way each customer configures and uses the system. Review the relevant documents and responsibilities during procurement.
Is Chronodesk ISO 27001 certified?
The current public wording is “ISO 27001 aligned”, not ISO 27001 certified. Do not describe Chronodesk as certified unless a current certificate can be provided.
Is data encrypted?
Chronodesk's public security information states that data at rest uses AES-256 encryption and data in transit uses TLS 1.2 or later.
Can Chronodesk be hosted in the UK?
[Insert a definitive answer only after the available cloud regions, backup locations and commercial conditions are confirmed.] Until then: talk to Chronodesk about your hosting and data-residency requirements before purchase.
Does Chronodesk support SSO?
The current Enterprise plan includes SAML SSO and OAuth. Confirm identity-provider compatibility and the exact configuration during evaluation.
Can we review security documents?
[List the documents that can genuinely be provided, such as a DPA, subprocessor list, security overview or test summary, and state whether an NDA is required.]
Bring your security and procurement questions.
Discuss the information, access, deployment and contractual requirements that matter to your organisation.