86Hours
Product
Product overviewAll featuresEvidence packsCalculator
How it works
Solutions
Small businessesSole tradersFreelancersTradesAgenciesBookkeepers
Pricing
Resources
Resource libraryGuidanceHelp centreCalculator
Trust
Menu
ProductHow it worksSolutionsPricingResourcesTrustContactCreate accountSign in
Sign inCreate account →

Security

Evidence deserves careful handling.

86Hours is designed around authenticated access, private storage, limited permissions and explicit user approval.

Last updated: 30 July 2026

Account isolation

Protected case routes and evidence-file requests apply authenticated account, tenant, workspace and case checks. Case files are not published as public links, and evidence responses are marked private and non-cacheable.

First-party account security

86Hours operates its own email-and-password account system inside the application. Passwords are protected with a unique random salt and PBKDF2-HMAC-SHA256 using 600,000 iterations; readable passwords are never stored. Sessions use random 256-bit tokens, and only token hashes are retained server-side. Browser cookies are marked Secure, HttpOnly and SameSite. A random private recovery code is shown once when an account is created; only its hash is retained and replacing or using it invalidates the previous code.

Protected evidence storage

Uploaded files are stored under non-guessable keys in private object storage. Download routes verify the account, case and evidence scope before returning a file. Supported uploads are size-limited, and unavailable security-dependent functions remain disabled.

Connected email

Google access and refresh tokens are encrypted before storage. 86Hours requests outbound-send access only for the available integration, never asks for the mailbox password and does not claim to synchronise replies.

Payments

Card details are entered on Stripe's hosted checkout and are not stored by 86Hours. Signed webhook events update package access after provider confirmation. Customers manage payment methods, invoices and subscription cancellation through Stripe's secure customer portal.

Operational controls

  • Security headers and transport protection on public responses
  • Origin checks and separate IP/email rate limits on account actions
  • Private, account-scoped access to case records and evidence
  • Restricted owner access to private administrative routes
  • Documented privacy, retention and deletion request routes

What this page does not claim

86Hours does not claim a security certification, absolute security, platform-wide immutable evidence or independent forensic verification. Functions that have not completed security and recovery checks remain unavailable.

Your part

Use a unique password of at least 12 characters, preferably stored in a password manager. Review recipients and attachments before sending, keep original business records, remove access for people who no longer need it and contact support promptly if you suspect unauthorised access.

Reporting a security concern

Please report a suspected security or privacy issue through the support address shown in the privacy notice. Include enough detail for the issue to be investigated, but do not send passwords, secret keys or unnecessary personal information.

86Hours

Guided unpaid-invoice recovery and evidence organisation for UK businesses. Administrative software—not legal advice or court representation.

ProductOverviewFeaturesEvidence packsPricingInvoice recovery
SolutionsSmall businessesSole tradersFreelancersTradesFor bookkeepersBookkeeper workspaceSmall-business recovery
ResourcesGuidesGuidanceLate-payment guideChasing an invoiceCustomer has not paidHelp centreBilling helpCalculator
CompanyAboutContactTrustSecurityService statusChangelog
LegalPrivacyTermsCookiesAccessibilityAcceptable use
AccountSign inCreate accountAccount help
© 2026 86Hours