One command center. Every client.
Enterprise-grade timesheets, leave, and project tracking for agencies managing multiple clients — secured to ISO/IEC 27001:2022 standards.
Security controls aligned with ISO/IEC 27001:2022Everything a multi-client operation needs, in one system
Multi-tenant Organizations
Every client is its own isolated Organization — its own users, teams, and projects, never mixed with another.
Projects & Assignment
Managers create Projects and staff Employees onto them; time is logged against real project work.
Weekly Timesheets & Leave
A fast weekly grid, invoice-hours calculation, and a full leave request/approval workflow.
Subscription Billing Built In
Free, Starter, Growth, and Enterprise plans with enforced seat limits and Stripe-powered checkout.
Full Audit Logging
Every admin, billing, and login action is logged and searchable — nothing happens invisibly.
Security-First Design
Account lockout, enforced password policy, encrypted secrets, and controls aligned with ISO/IEC 27001:2022.
Up and running in three steps
Choose a plan & get set up
Pick a plan below and reach out — we'll set up your Organization and its first Account Admin.
Add your team & projects
Your Account Admin creates Managers and Employees; Managers create Projects and staff people onto them.
Log time, request leave, approve
Employees log weekly hours and request leave; Managers approve — all tracked, exportable, and audited.
Built for teams that handle client data
iPhenomenon's technical controls are aligned with a family of ISO/IEC information security standards — 27001:2022 (information security management), 27017:2015 (cloud security), 27018:2019 (protection of personal data in the public cloud), and 27701:2019 (privacy information management) — plus the EU's GDPR data-subject rights. We say "aligned with," not "certified": certification covers an organization's operating management system, not a codebase, and we'd rather be precise than impressive.
Tenant Isolation
Every Organization is a hard boundary — data, users, and projects for one client are never visible to another, enforced server-side on every query.
Full Audit Logging
Every admin, billing, and login action is recorded to an immutable audit log, searchable by Super Admins — nothing happens invisibly.
Encrypted Secrets at Rest
Stripe API keys and other sensitive credentials are encrypted at rest and never redisplayed once saved.
Account Lockout & Password Policy
Accounts lock after 5 failed logins; passwords require a mix of character classes, hashed with PBKDF2-SHA256.
Role-Based Access Control
Four enforced roles — Super Admin, Account Admin, Manager, Employee — each checked on both the route and the data query.
Encryption & Secure Headers
TLS in transit, CSRF tokens on every state-changing form, and HSTS/anti-clickjacking headers on every response.
Your Data, Your Rights
Every user can export a complete copy of their data or permanently anonymize their own account on demand — GDPR Art. 15/17/20 and ISO/IEC 27701 PII-principal rights, built in.
Serverless, No Server to Harden
The platform runs entirely on managed, serverless AWS infrastructure — no OS or VM for an attacker to find unpatched, aligned with ISO/IEC 27017 cloud security guidance.
Transparent Subprocessors
Exactly two named subprocessors — AWS and Stripe — disclosed in our Privacy Policy, with data shared limited to what each needs to do its job, per ISO/IEC 27018.
A plan for every size of team
Start free instantly, or pick a paid plan and send us a message below.
Questions, sales, or support
Send us a message and our team (a Super Admin) will get back to you.