Legal

Security

Last updated June 2026

Hosting & data residency

Application data and files are hosted with reputable US-based cloud infrastructure. Uploaded files are stored in US object storage with SHA-256 integrity checksums.

Encryption

Data is encrypted in transit using TLS. Sensitive integration tokens (e.g., QuickBooks Online, Xero, Gmail) are encrypted at rest with per-workspace keys.

Access control (RBAC)

Role-based access enforces least privilege. Subcontractors and field technicians are job-scoped and cannot see pricing, margin, or customer history. Owners and dispatchers have elevated, audited access.

Authentication & MFA

Staff sign in with email/password or magic link. Optional TOTP multi-factor authentication is available for Owner/Admin roles. Sessions use signed tokens.

Malware scanning

Uploaded media is scanned for malware in the background before it is served, and checksums detect tampering.

Auditability

Signed field documents, AI review decisions, and closeout packages are recorded to support a defensible audit trail. AI outputs never auto-post to your ledger without human approval.

Backups & resilience

We design for resilient, offline-first field operation and recovery rather than zero-failure promises. Payment or connectivity failures after reconnection never corrupt completed field records.

Payment security

Card payments are processed by Stripe, a PCI-DSS Level 1 certified provider. We do not store full card numbers on our servers.

Vulnerability management

We keep dependencies current and monitor for security issues, applying fixes on a risk-prioritized basis.

Responsible disclosure

Found a vulnerability? Please report it privately to chris.suht@gmail.com so we can investigate and remediate before public disclosure.

We use essential cookies to run SiteControlHQ and optional analytics to improve it. See our Privacy Policy.