User Guide
Licensing & deployment
Pick a tier, choose deployment mode, decide online vs offline licensing.
4 license tiers
🆓
Trial
Free · up to 3 users · 14 days. Auto-converts to Team when you upgrade.
👥
Team
Up to 5 users · one-time. Optional $49/year maintenance.
🏢
Business
Up to 15 users · one-time. Custom PDF + email branding.
🏛️
Enterprise
Unlimited users · one-time. Phone + email support. Dedicated AM.
Every tier has every feature. Tier difference is user count cap, not feature gating.
Online vs offline licensing
🌐
Online (default)
App phones home every 24 hours to validate the license against our license server. Allows remote revocation if a license is compromised. 7-day grace period if the server is unreachable.
🔌
Offline (by request)
App never contacts our license server. The
.lic is RSA-verified locally + email-matched against the JWT's customer_email claim. For air-gapped / VPN-only deployments.Defense-in-depth across both modes
RSA-4096 signature on the JWT (private key never leaves the license server). Embedded
customer_email claim must match what the customer types at setup. Embedded exp claim caps usage at maintenance / trial expiry. Tampering breaks the signature — no path to bypass.3 deployment modes
🪟
Windows native
NSIS installer registers TimeTrackPro as a Windows Service via NSSM. Auto-starts on boot, crash-restart loop, log capture.
🍎
macOS native
DMG installer + launchd daemon at
/Library/LaunchDaemons/com.quantumit.ttp.plist. Auto-starts at boot.🐳
Docker
Compose file maps host:3847 → container:3847 + bind-mounts
data/. Customer downloads tarball + loads locally — no docker login.Docker install:
gunzip -c ttp-docker-vX.Y.Z.tar.gz | docker load docker compose up -d
SSL / HTTPS — 4 modes
HTTP-only (default)Self-signedUploaded certLet's Encrypt
All three install modes ship with bundled Caddy for optional HTTPS termination. Self-signed requires the customer to trust the local CA per device. Let's Encrypt requires public hostname + port 80 + 443 reachability.
Tip
Switch SSL modes any time under Settings → SSL. The wrapper re-renders the Caddyfile + restarts Caddy. No app downtime — Node keeps serving on 3847; only the HTTPS proxy bounces.
Upgrades
Releases ship as signed installers + Docker tarballs. Stop the service, run the new installer, restart. First-boot bundle applies any pending migrations idempotently before the server starts.