Legal & Compliance

Time Traker is built for organizations that face real audits. Here's what we support.

DCAA-compliant

Daily entry enforcement, immutable change history, supervisor sign-off workflow, and exportable audit trail meeting DCAA Manual for Contract Audit requirements.

FAR-aligned

Labor distribution and timekeeping records aligned with FAR 31.201 cost-allowability principles.

Data security

TLS 1.2+ in transit, AES-256 at rest, SOC 2 Type II controls, annual penetration testing, role-based access control.

DCAA timekeeping statement

Time Traker records the date, time, project, task and labor category of every entry; locks entries upon supervisor approval; maintains an immutable change log with user, timestamp and reason for change; and produces audit-ready reports on demand. Floor-check support is available on Enterprise plans.

FAR 31.201 alignment

Labor cost allocation supports direct vs. indirect categorization, project-level distribution, and unallowable cost flagging. Reports can be exported to support incurred-cost submissions.

Data protection & privacy

See our Privacy Policy for full details on GDPR and CCPA rights, data retention, and subprocessor disclosures. Data Processing Addendums (DPAs) are available on request — contact support@timetraker.com.

Subprocessors

Time Traker uses a small number of vetted subprocessors for hosting, email delivery, and analytics. A current list is provided to enterprise customers under NDA.

Reporting a security issue

Email support@timetraker.com with the subject line "Security Report". We acknowledge within 24 hours.