User Guide

Licensing & deployment

Pick a tier, choose deployment mode, decide online vs offline licensing.

4 license tiers

🆓

Trial

Free · up to 3 users · 14 days. Auto-converts to Team when you upgrade.
👥

Team

Up to 5 users · one-time. Optional $49/year maintenance.
🏢

Business

Up to 15 users · one-time. Custom PDF + email branding.
🏛️

Enterprise

Unlimited users · one-time. Phone + email support. Dedicated AM.

Every tier has every feature. Tier difference is user count cap, not feature gating.

Online vs offline licensing

🌐

Online (default)

App phones home every 24 hours to validate the license against our license server. Allows remote revocation if a license is compromised. 7-day grace period if the server is unreachable.
🔌

Offline (by request)

App never contacts our license server. The .lic is RSA-verified locally + email-matched against the JWT's customer_email claim. For air-gapped / VPN-only deployments.
Defense-in-depth across both modes
RSA-4096 signature on the JWT (private key never leaves the license server). Embedded customer_email claim must match what the customer types at setup. Embedded exp claim caps usage at maintenance / trial expiry. Tampering breaks the signature — no path to bypass.

3 deployment modes

🪟

Windows native

NSIS installer registers TimeTrackPro as a Windows Service via NSSM. Auto-starts on boot, crash-restart loop, log capture.
🍎

macOS native

DMG installer + launchd daemon at /Library/LaunchDaemons/com.quantumit.ttp.plist. Auto-starts at boot.
🐳

Docker

Compose file maps host:3847 → container:3847 + bind-mounts data/. Customer downloads tarball + loads locally — no docker login.

Docker install:

gunzip -c ttp-docker-vX.Y.Z.tar.gz | docker load
docker compose up -d

SSL / HTTPS — 4 modes

HTTP-only (default)Self-signedUploaded certLet's Encrypt

All three install modes ship with bundled Caddy for optional HTTPS termination. Self-signed requires the customer to trust the local CA per device. Let's Encrypt requires public hostname + port 80 + 443 reachability.

Tip
Switch SSL modes any time under Settings → SSL. The wrapper re-renders the Caddyfile + restarts Caddy. No app downtime — Node keeps serving on 3847; only the HTTPS proxy bounces.
Upgrades
Releases ship as signed installers + Docker tarballs. Stop the service, run the new installer, restart. First-boot bundle applies any pending migrations idempotently before the server starts.