Last updated: September 21, 2026
Timero holds the hours, clients and budgets your business runs on. This page explains how we protect that data, what you can control yourself, and when we last reviewed the product for security problems.
In Settings → API keys you can see the API keys and connected AI assistants you have set up in a workspace, and remove any of them at any time. Removing one stops it working immediately.
We run security reviews on the parts of Timero that control sign-in and access to your data. Every possible issue is checked a second time before we rate it, and anything we find is tracked until it is fixed. To keep you safe, we do not publish details of open items.
| Date | What we reviewed | Result |
|---|---|---|
| September 17, 2026 | AI assistant service and shared data rules. We reviewed the whole AI assistant service as it runs in production, and the shared rules that decide which workspace a client, project, budget or time entry belongs to. Those rules are used by the app and by AI assistants alike. We also sent a small set of read-only requests to the live service. | Issues found and fixed. Some edits could have placed data under another company's workspace, and a removed member's keys could come back after a re-invite. Both are fixed and covered by tests. |
| September 16, 2026 | AI assistant connections. We reviewed the new sign-in that lets AI assistants such as Claude and ChatGPT connect to a workspace. We checked how access is approved, how long it lasts, how it is withdrawn, and that each connection stays inside one workspace with the permissions of the person who approved it. | No serious issues found. We also noted a few improvements, which we are working on. |
If you think you have found a security issue in Timero, please email us at hello@kendoo.co with the details. We read every report and will reply. Please give us a chance to fix the issue before sharing it publicly. See also our Privacy Policy and sub-processors.