
Security, Compliance & Trust
ShiftWatch is a cloud-based roster scheduling and workforce management platform designed to help mission-critical public service organizations manage staffing, scheduling, qualifications, overtime, coverage, and workforce accountability across single-site and multi-facility environments.
Security, availability, and confidentiality are incorporated into the design, operation, and support of the ShiftWatch service. This page provides information about the ShiftWatch service boundary, security practices, availability and confidentiality commitments, customer responsibilities, and applicable compliance activities.
Timeguard Solutions is a registered DBA of Goldschmitt and Associates LLC.
Information on this page applies specifically to ShiftWatch and does not represent the compliance scope of other Timeguard products
Security
Controls and practices designed to protect ShiftWatch systems and customer information.
Availability
Monitoring, backup, recovery, and operational practices designed to support reliable service.
Confidentiality
Controls designed to restrict access to customer information and protect it from unauthorized disclosure.
Compliance
Independent assurance and compliance activities applicable specifically to the ShiftWatch service.
ShiftWatch
Service Overview
ShiftWatch provides authorized users with tools to manage workforce scheduling and related operational activities, including:
- Roster and shift scheduling
- Staffing and coverage management
- Qualification-based assignments
- Overtime management
- Shift and post bidding
- Workforce reporting and analytics
- Audit logging and accountability
- Integration with approved HR and personnel systems
- Multi-facility workforce management
Every operation demands a different approach, which is why ShiftWatch is purpose-built for specific mission-critical public safety environments, ranging from individual facilities to enterprise wide deployments. Select a button below to learn more.
ShiftWatch System Boundaries
The ShiftWatch service includes the production application and supporting technology used by Timeguard Solutions to deliver the service to customers. ShiftWatch is a cloud-based application hosted within secure cloud infrastructure designed to support the security, availability, scalability, and reliability of the service.
Security
- Access restricted to authorized users
- Role-based permissions
- Encryption in transit and at rest
- Security logging and monitoring
- Vulnerability and patch management
- Controlled system changes
- Documented incident response practices
Availability
- System availability and performance monitoring
- Backup and recovery processes
- Incident management and escalation
- Controlled maintenance
- Business continuity and recovery planning
- Customer-specific service levels governed by applicable agreements
Confidentiality
- Customer information treated as confidential
- Access based on business need
- Authorized personnel and service providers subject to confidentiality requirements
- Controlled use and disclosure of customer information
- Data handling consistent with applicable agreements and policies
CUSTOMER RESPONSIBILITIES
Additional technical details may be made available to authorized customers through applicable security and compliance documentation.
Protecting ShiftWatch is a shared responsibility between Timeguard and its customers. Timeguard is responsible for the security and operation of the ShiftWatch service environment, while customers are responsible for the users, devices, networks, credentials, data, and configurations under their control.
Report a Security, Availability, Confidentiality, or Compliance Concern
- Customers, users, security researchers, and other external parties may report suspected security incidents, vulnerabilities, confidentiality concerns, availability issues, or compliance concerns involving ShiftWatch.
- Please do not send passwords, authentication tokens, Social Security numbers, or other highly sensitive information through ordinary email.
- Timeguard reviews reported security, availability, confidentiality, and compliance concerns and routes them to appropriate personnel for investigation and response.
- Additional information may be requested to assist with investigation and resolution.
Sign up to our newsletter
Corporate Certifications
Timeguard Solutions is a registered DBA of Goldschmitt and Associates LLC (G&A). G&A's integrated Quality Management System is ISO 9001, ISO/IEC 27001, ISO/IEC 20000-1, and CMMC Level 2 certified, and CMMI Level 3 appraised for both Services and Development, proving our ability to produce repeatable high-quality results - every time.
Timeguard is working with an independent service auditor to evaluate controls applicable to the ShiftWatch service in accordance with SOC 2 AICPA Trust Services Criteria.
Additional security and compliance documentation may be available to authorized customers through the Timeguard Solutions Customer Trust Center.

SHIFTWATCH SECURITY FAQ
ShiftWatch Security, Compliance & Trust
Where is ShiftWatch hosted?
ShiftWatch is a cloud-based application supported by secure, scalable infrastructure and operational practices designed to promote the security, availability, and reliability of the service.
Is ShiftWatch data encrypted?
Yes. ShiftWatch uses encryption to protect customer data both in transit and at rest. Additional safeguards, including access controls and logical separation of customer data, are used to help protect information from unauthorized access or disclosure.
How is access to ShiftWatch controlled?
ShiftWatch uses role-based access controls to limit access based on a user's authorized responsibilities. Customers manage access for their users and assign appropriate roles and permissions based on their organizational and operational requirements.
Access to the supporting ShiftWatch environment by Timeguard personnel is restricted to authorized individuals with a legitimate business need.
Does ShiftWatch maintain audit logs?
Yes. ShiftWatch maintains audit and activity logging designed to support accountability, operational review, security monitoring, and investigation of reported issues.
Access to audit information is restricted based on authorized roles and responsibilities.
How does Timeguard address vulnerabilities?
Timeguard maintains processes for identifying, evaluating, prioritizing, and addressing vulnerabilities that could affect ShiftWatch or its supporting environment.
Identified vulnerabilities are evaluated based on factors such as severity, potential impact, and risk, and appropriate remediation activities are tracked through resolution.
How does Timeguard manage application changes?
Changes to ShiftWatch are managed through documented development and change-management processes designed to support the security and stability of the production environment.
Changes are reviewed, tested, documented, and deployed through controlled processes before being introduced into the production environment.
How does Timeguard support service availability?
Timeguard maintains operational practices designed to support the continued availability and recovery of ShiftWatch. These include system monitoring, backup and recovery processes, incident management, controlled maintenance, and business continuity and recovery planning.
Specific availability or service-level commitments may be established through applicable customer agreements.
How does Timeguard protect confidential customer information?
Timeguard treats customer information processed through ShiftWatch as confidential and uses administrative, technical, and operational safeguards designed to protect it from unauthorized access, use, or disclosure.
Access to customer information is restricted to authorized personnel and service providers with a legitimate business need and appropriate confidentiality obligations. Customer information is also protected through measures including encryption and access controls.
Does Timeguard use third-party service providers?
Yes. Timeguard uses select third-party technology and service providers to support the operation and delivery of ShiftWatch. These relationships are managed through processes designed to address applicable security, confidentiality, availability, and operational risks.
Additional information regarding relevant service providers may be available to authorized customers upon request.
What security responsibilities belong to customers?
Protecting ShiftWatch is a shared responsibility between Timeguard and its customers.
Customers are responsible for managing authorized users, assigning appropriate roles and permissions, protecting account credentials, securing customer-managed devices and networks, managing customer-controlled systems and integrations, and ensuring that information submitted to ShiftWatch is appropriate and authorized.
Customers should also promptly notify Timeguard of suspected compromised credentials, unauthorized access, security incidents, confidentiality concerns, or other events that could affect the security or availability of ShiftWatch.
How do I report a suspected security incident?
Suspected security incidents, vulnerabilities, unauthorized access, confidentiality concerns, or other security-related issues involving ShiftWatch should be reported promptly to Timeguard using our Security Reporting Form.
When reporting an issue, please provide a description of the concern, when it was observed, the affected ShiftWatch feature or service, and relevant supporting information.
Please do not send passwords, authentication tokens, Social Security numbers, or other highly sensitive information through ordinary email.
How can customers obtain additional security documentation?
Authorized customers may request additional ShiftWatch security and compliance information by contacting us via our Security Reporting Form
Depending on availability and applicable confidentiality requirements, documentation may include security policies or summaries, system information, business continuity information, compliance documentation, independent assurance reports, and other materials used to support customer security and risk assessments.
Certain information may require authentication, an applicable confidentiality agreement, or other authorization before it can be provided.
Does the ShiftWatch SOC 2 scope include VisitWatch or TimeWatch?
No. The SOC 2 examination and related compliance information described on this page apply specifically to ShiftWatch and the systems, infrastructure, processes, and services included within the defined ShiftWatch examination scope.
VisitWatch, TimeWatch, and other Timeguard products are not included in the ShiftWatch SOC 2 scope unless they are expressly identified as being included in applicable audit documentation.
Additional Security Information
Authorized customers may access additional ShiftWatch security and compliance information, including applicable audit documentation, security policies or summaries, architecture information, business continuity information, and other materials made available for customer due diligence.
Privacy Policy
Learn how Timeguard handles information collected through its website and services.
Terms of Service
Review the terms and conditions applicable to use of Timeguard's services.
General Inquiries and Demos
For sales, demonstrations, or general questions, please use our Contact Us page.
Last Page Update: 08/14/2026







