TimeTonic is a core IT platform available in SaaS (Software as a Service) mode, hosted in France in a sovereign environment that meets the highest corporate requirements in terms of security, resilience, and compliance.
From physical protection of infrastructure with biometric control to detailed management of user access rights, based on the principle of "privacy & security by design," including encryption of communications, password hashing and salting, daily backups on remote servers, data security, software quality control, and a highly secure architecture. security by design," to communication encryption, password hashing and salting, daily backups on remote servers, data security, software quality control, and a highly resilient and scalable architecture with WAF, load balancing, and automatic failover, every aspect of our platform and environment is designed to protect your information, ensure high availability, and guarantee a smooth and efficient experience.
Our infrastructures are hosted in certified sovereign data centers (ISO 27001, HDS, HIPAA, SOC 1, 2, and 3, GDPR, etc.), in a hybrid cloud infrastructure combining public and private environments.
This hybrid model allows us to leverage the scalability of the public cloud for services with high load variability, while benefiting from the isolation and enhanced control of the private cloud for critical or sensitive components of the platform.
The infrastructure used is based on a redundant architecture, ensuring high availability and service continuity. The hybrid cloud optimizes resilience by intelligently distributing loads and enabling rapid failover between environments in the event of an incident or overload.
The servers are deployed in data centers located exclusively in France, hosted by French operators, ensuring full compliance with European regulations on personal data protection (GDPR) and digital sovereignty not subject to the US Cloud Act.
With secondary sites for redundancy and backups also located in France but several hundred kilometers away from the primary sites, TimeTonic ensures optimal resilience and service availability.
The deployment architecture is designed to be modular, scalable, and easily interconnectable with third-party systems.
Our choice of suppliers and our architecture allow us to offer fully dedicated environments as an option, with HDS (Health Data Hosting) and Secnumcloud certification (the highest level of security and sovereignty required by the French government for cloud service hosting).
TimeTonic is hosted by OVHcloud, a major European hosting provider.
Our hosting provider's numerous certifications can be viewed here:
The hosting guarantees 99.999% availability and the platform offers an overall availability rate of over 99.95%.
Access to TimeTonic is based on strong authentication, with SSO (SAML v2) support for seamless integration with corporate directories, and a two-factor authentication (2FA) option for enhanced security.
Each user has rights calibrated according to their role (administrator, contributor, read-only, API), allowing for strict compartmentalization of information.
All sensitive connections and actions are tracked in audit logs, ensuring complete traceability of usage. In the event of a fraudulent login attempt, automatic locking and IP address restriction mechanisms are activated.
Access is strictly controlled using application firewalls (WAF), intrusion detection systems (IDS/IPS), and multi-factor authentication for all administrative access.
Password and automatic logout policies can be configured on demand, with passwords required to contain at least 8 characters, including an uppercase letter, a lowercase letter, a number, and a special character, and automatic logout after 4 hours of inactivity.
In addition, TimeTonic offers fine-grained user rights management, allowing, for example, the isolation of end-user data by creating isolated "mirror views" in separate workspaces. This ensures greater security by avoiding overloading end users with unauthorized or unnecessary data for their daily management, thus simplifying the user interface and increasing security, the quality and ergonomics of the applications created.
TimeTonic's dynamic filter options allow visibility or modification rights to be granted per user or per user group, including conditionally: for example, the same view can be filtered to display only specific information accessible according to the TimeTonic ID of the person logged in or according to a particular status or field with a particular value.
In addition, in the business plan, administrators have advanced options to manage user rights, define the applications to which they have access, and what type of rights they have.
Our infrastructure is hosted in certified data centers (ISO 27001, HDS, etc.), located exclusively in France. These centers are subject to strict physical controls: access via personalized badges, video surveillance, alarms, and security personnel.
Power is supplied by redundant systems (UPS) to ensure maximum availability, and energy efficiency is optimized (PUE < 1.3), in line with our environmental commitment.
Data security is at the heart of our architecture. All communications between users and servers are encrypted via TLS 1.3, with HSTS enabled to prevent man-in-the-middle attacks.
Files are encrypted on the fly before being stored, and sensitive data in databases can also be encrypted using a secure encrypted field that can be configured directly by your own application developers.
Your data is stored in France in our sovereign infrastructure, and no data is stored or transmitted outside the European Union, unless you yourself choose to use services external to TimeTonic via our Application Programming Interfaces (APIs) or our automations with Webhook calls.
We develop and host our own database, rapid search, and automation engines to ensure that no data is transferred outside our infrastructure.
We even offer the option of hosting LLMs (e.g., Mistral) in our own infrastructure to ensure that no data, queries, or responses are transmitted outside during AI automation.
We also offer this option for Serenytics (dashboards) and n8n (automation platform) servers.
A complete copy of the data, files, and all application settings is backed up daily and stored for 30 days in our infrastructure at remote sites located several hundred kilometers from the production sites.
TimeTonic transfers modified data to a backup workspace in CSV-compatible XML format every day. We also offer the option, on request, to transfer all data and files to your own backup servers at regular intervals via SFTP, and you can retrieve all your information at any time via CSV export, including a zip file containing all your files.
For added security and ease of management, deleted records are kept in your data table's recycle bin. You can restore these records or delete them permanently if you are an administrator.
TimeTonic automatically saves the date and time of the last modification, as well as the complete history of all data modifications, in a dedicated field containing the date and time of the modification, the ID of the person who made the modification, and the previous and new values, for complete traceability. This is ideal for teamwork or for understanding why a particular change was made.
For Business plan users, data can be stored in dedicated isolated databases, ensuring total compartmentalization, optimal performance uncontaminated by other users, and rapid restoration in the event of unwanted deletion.
A complete SecNumCloud environment can also be set up, with a dedicated architecture and its own servers.
User access logs are accessible with the Business plan.
Your data and files are your sole property, and under no circumstances does TimeTonic access them (except at your express request when you temporarily invite the support team to access your workspaces, for example) or give third parties access to your data.
You can also delete your account and workspaces at any time. Your data will then be completely deleted from our servers after 30 days of daily backup retention.
At TimeTonic, software quality is not just a goal: it is a cornerstone of our development process. We have implemented a continuous validation approach (Continuous Integration/Continuous Deployment) combining methodological rigor and cutting-edge tools to ensure the stability, performance, and security of our SaaS platform.
Each feature developed undergoes several levels of testing:
Tests are triggered automatically with each commit in our CI/CD pipeline. No code goes into production without passing these steps.
Our testing tools also include security checks:
Before each release:
Once online, the platform is actively monitored (via Signoz, Graylog, Grafana, etc.) to detect anomalies, monitor performance, and automatically alert our team in the event of an incident.
TimeTonic offers you a flexible, powerful, sovereign, secure platform, hosted in France, designed for the most demanding organizations, and built on a solid foundation of security, reliability, and compliance. Whether you are a public company, a local authority, or a large private company, your applications and data are in good hands.