eHour
eHour is cloud-based timesheet, attendance and project time tracking software for public sector organisations. It captures working time, start and end times, billable and non-billable hours and expenses, manages approvals and project budgets, and provides auditable management and financial reporting for transparent cost control.
Features
- Weekly timesheets, timers and Jira-based time tracking
- Project, task and activity time recording
- Attendance tracking using start and end times
- Billable and non-billable hours, rates, costs and revenue
- Time and financial project budgets with progress monitoring
- Expense recording with receipt capture and approval
- Timesheet approvals, automatic reminders and locked approved hours
- Real-time reporting, dashboards, exports, API and Power BI access
- Role-based access, SSO and automated SCIM user provisioning
- Secure service with ISO 27001 certified information security
Benefits
- Make timesheet and attendance recording simple for employees
- Reduce missing and late timesheets through reminders and easy entry
- Keep approved hours final, auditable and ready for further processing
- Provide reliable time and expense data for payroll and invoicing
- Monitor project budgets, costs, revenue and utilisation in real time
- Identify budget overruns and unrecorded time earlier
- Improve financial accountability across teams and departments
- Give managers timely insight without manually combining spreadsheets
- Reduce user administration through SSO, SCIM and role-based access
- Support internal controls, working-time policies and audit requirements
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 3 8 1 2 3 3 5 2 0 2 7 4 0 1
Contact
TE-CON B.V.
Thies Edeling
Telephone: +31 202615286
Email: info@ehour.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Project and portfolio management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- There are no material service constraints. The service is available to users via a standard web browser and is maintained without planned customer-specific downtime.
- System requirements
-
- Modern web browser with JavaScript and cookies enabled
- Internet connection to access the cloud-based service
- Email access for notifications and account communication
- User account with role-based access permissions
User support
- Email or online ticketing support
- Yes
- Support response times
- One business day
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- The web chat is provided through an in-application widget that allows users to communicate directly with a support operative using text-based messaging. The service does not require voice interaction. Accessibility features depend on the user’s device, browser and any assistive technologies in use. No formal accessibility standard is currently certified for the web chat component.
- Web chat accessibility testing
- No formal testing of the web chat has been conducted with assistive technology users. The web chat functionality is provided as a standard text-based widget within the application. Any accessibility experienced by users depends on their device, browser and assistive technologies in use.
- Onsite support
- No
- Support levels
-
The service is provided with a single, standard level of support for all customers. Support is included in the service subscription at no additional cost. There are no tiered support levels.
Support is provided via email and in-application web chat during standard business hours (9am to 5pm UK time, Monday to Friday). Response times are provided on a best-efforts basis.
The service does not include a dedicated Technical Account Manager or Cloud Support Engineer. All customers receive the same level of support from the support team. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Users are supported through in-application onboarding that guides them through initial setup and core functionality. This is complemented by online “Getting Started” guides and user documentation available via the knowledge base.
Additional support is available via email or web chat during business hours. No on-site training is required to start using the service. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can extract their data directly from the service using built-in export functionality.
Standard exports are available for reports, projects, clients, users and teams in commonly used file formats suitable for offline use and import into other systems. Data can be exported by authorised users prior to contract termination.
No specialist tools are required to perform data extraction. - End-of-contract process
-
At the end of the contract, access to the service will cease in line with the agreed contract end date.
Prior to contract termination, authorised users can export their data using the standard export functionality included in the service. This includes reports and core configuration data such as projects, clients, users and teams.
Data extraction using the standard export features is included in the contract price. No mandatory exit fees apply.
Following contract termination, customer data is retained for a limited period in accordance with our data retention policy, after which it is securely deleted.
Any additional support beyond standard data export, such as bespoke data extraction or extended data retention, can be discussed separately and may incur additional costs if requested. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding documentation is provided through a web-based HTML knowledge base. The documentation is accessible via standard web browsers without the need for additional software or downloads. Content is text-based and structured for online reading.
Accessibility depends on the user’s browser, device and any assistive technologies in use. No formal accessibility standard has been certified.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile version supports time tracking. Reporting, configuration and administrative management are provided via the desktop service.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service provides a web-based user interface accessible via standard web browsers, allowing users to record time, manage projects, and view reports. In addition, a REST-based API is available to support integrations with third-party systems.
- Accessibility standards
- None or don’t know
- Description of accessibility
- No formal testing has been conducted specifically with users of assistive technologies. The service interface is accessed through standard web browsers and relies on the accessibility features provided by the user’s operating system, browser, and any assistive technologies in use. Accessibility feedback may be addressed on a case-by-case basis if raised by users.
- Accessibility testing
- No formal testing has been conducted specifically with users of assistive technologies.
- API
- Yes
- What users can and can't do using the API
-
The API allows authorised users to manage core entities including clients, projects, tasks, users and teams. It supports creating and updating time entries and expenses, and retrieving data for reporting purposes.
The API can be used for system integration and automation, including user lifecycle management through SCIM. All actions are subject to authentication, role-based permissions and validation rules. Certain configuration and administrative functions remain available only through the web interface. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- The service is delivered on a multi-tenant cloud architecture hosted on AWS. Capacity is managed through automatic scaling of compute resources based on demand, ensuring consistent performance as usage increases.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export their data using built-in export functionality within the service and via the API.
Standard exports are available for reports and configuration data, including projects, clients, users and teams. Reports can be exported in common formats such as CSV, Excel and PDF.
The API allows programmatic access to data for automated extraction and integration with external systems. - Data export formats
-
- CSV
- Other
- Other data export formats
- XLSX
- Data import formats
- Other
- Other data import formats
- XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is provided on a best-efforts basis. eHour uses best efforts to maintain 99.5% availability during business hours (09:00–18:00 CET).
Planned maintenance is carried out outside business hours wherever reasonably possible and is announced in advance when feasible.
No formal service credits or refunds are provided if the availability target is not met. Availability commitments and maintenance arrangements are governed by the applicable terms and conditions. - Approach to resilience
- The service is hosted on AWS and designed for resilience using managed cloud infrastructure. The platform uses redundant components and automatic scaling to handle varying load and reduce the impact of failures. Backup and recovery procedures are in place to support service continuity.
- Outage reporting
- Service availability and incidents are communicated via a public status dashboard. The dashboard provides up-to-date information on current incidents, planned maintenance and historical outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted to authenticated users within the application.
For support requests, user identity is verified by matching the request against the registered account details, such as the email address associated with the user or organisation. Account-specific actions are only performed after successful verification.
In-application support features are only available to authenticated users. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate an ISO/IEC 27001:2022 certified Information Security Management System (ISMS). This includes documented information security policies and procedures such as access control, incident management, change management and vulnerability management.
Information security responsibilities are formally assigned and compliance is monitored through defined procedures, logging, reviews and internal and external audits. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration and changes are managed through defined internal change management procedures aligned with our ISO 27001 certified ISMS. Service components and configurations are version-controlled and tracked throughout their lifecycle.
All changes are reviewed before implementation, including an assessment of potential security and operational impact. Changes are tested prior to deployment and are rolled out in a controlled manner to minimise risk and service disruption. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerabilities are identified through a combination of automated dependency scanning, cloud provider security notifications, and periodic external penetration testing. Potential impact is assessed based on risk and exposure. Security patches are prioritised and deployed as part of our regular release and maintenance process, with critical fixes applied as soon as reasonably possible. Information about emerging threats is sourced from trusted vendors, security advisories, and penetration test reports. All identified vulnerabilities are tracked and remediated in line with our internal security procedures.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The service uses protective monitoring based on application and infrastructure logging. Logs and audit trails are continuously collected and reviewed to identify unusual activity, access anomalies or potential security incidents. Automated alerts are configured for critical events. When a potential compromise is identified, it is investigated promptly and handled according to the incident management process. Mitigating actions are taken where required and incidents are recorded and reviewed. Initial response to security incidents typically occurs within 24 hours.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a defined incident management process aligned with ISO 27001. Common security and availability incidents follow documented procedures. Users can report incidents via email or in-application support. All incidents are logged, assessed for impact, and assigned an owner. Where required, affected customers are informed of incidents and progress updates. Post-incident reviews are performed to identify root causes and corrective actions, and incident records are retained for audit purposes.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A 14-day free trial is available with full access to all features. A paid subscription is required after the trial period ends.
- Link to free trial
- https://getehour.com/signup/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Thursday 17 October 2024
- What the ISO/IEC 27001 doesn’t cover
- Not applicable. The ISO/IEC 27001 certification covers the full scope of the eHour SaaS service, including development, hosting, operations, and support.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
-