Security
Data & security
Last updated:
Timastra keeps the public website separate from product accounts, limits the data collected here, and provides a direct path for security reports. Card details go to the payment provider's checkout, never to this website.
Website safeguards
This website uses HTTPS and browser safeguards that help protect connections and restrict unwanted scripts, embedding and permissions. It does not use advertising trackers or third-party analytics services; visits are counted with aggregate statistics described in the privacy policy. Interactive demos open in their respective applications. Contact email links open your email app.
Payment safeguards
This website does not collect card or bank details. Where a product bills through Paddle, payments started in the product finish on timastra.com/pay in Paddle's secure checkout, and card details go to Paddle, not to this website. For any purchase, review the seller and named payment provider in the order summary before entering payment information.
Financial connectivity principles
Where a product offers a bank or financial-account connection, it is permissioned and handled through a named connectivity provider. Before connection, users are told:
- which data is requested, from which selected accounts, and why;
- which features require the data and how long access is intended to continue;
- which third party facilitates the connection; and
- how to request disconnection, revoke access, or request deletion where applicable.
We will request the minimum practical data and permissions for the disclosed purpose. Provider tokens and secrets will remain server-side and will not be exposed in browser code. Timastra will not ask users to email or directly disclose their bank login credentials.
Incident and vulnerability reports
To report a suspected security issue, email support@timastra.com with the subject “Security report”, a concise description and safe reproduction steps. Do not include live credentials, card data, or unnecessary personal information, and do not disrupt systems or access data that is not yours. Our security contact is also published at timastra.com/.well-known/security.txt.
Security information and assurance
This page describes the public website’s safeguards and product security principles. For deployment-specific controls or independent assurance, contact Timastra before relying on a certification or regulated-service requirement.