Security
Last updated June 2026
Hosting & data residency
Application data and files are hosted with reputable US-based cloud infrastructure. Uploaded files are stored in US object storage with SHA-256 integrity checksums.
Encryption
Data is encrypted in transit using TLS. Sensitive integration tokens (e.g., QuickBooks Online, Xero, Gmail) are encrypted at rest with per-workspace keys.
Access control (RBAC)
Role-based access enforces least privilege. Subcontractors and field technicians are job-scoped and cannot see pricing, margin, or customer history. Owners and dispatchers have elevated, audited access.
Authentication & MFA
Staff sign in with email/password or magic link. Optional TOTP multi-factor authentication is available for Owner/Admin roles. Sessions use signed tokens.
Malware scanning
Uploaded media is scanned for malware in the background before it is served, and checksums detect tampering.
Auditability
Signed field documents, AI review decisions, and closeout packages are recorded to support a defensible audit trail. AI outputs never auto-post to your ledger without human approval.
Backups & resilience
We design for resilient, offline-first field operation and recovery rather than zero-failure promises. Payment or connectivity failures after reconnection never corrupt completed field records.
Payment security
Card payments are processed by Stripe, a PCI-DSS Level 1 certified provider. We do not store full card numbers on our servers.
Vulnerability management
We keep dependencies current and monitor for security issues, applying fixes on a risk-prioritized basis.
Responsible disclosure
Found a vulnerability? Please report it privately to chris.suht@gmail.com so we can investigate and remediate before public disclosure.
