Legal and trust
What is genuinely in place, and what we do not claim.
This page describes controls built into the application today. It deliberately contains no certification, audit or uptime claim, because we hold none.
Access control
- Every person signs in with their own account. There are no shared logins.
- Roles decide what a person can do, and branch assignment decides what they can see.
- Access rules are enforced at the database, not only hidden in the interface.
- Elevated roles cannot be granted by signing yourself up; a new self-registered account gets the lowest level.
- Membership can be suspended and restored without deleting the person's history.
Records and evidence
- Photos and evidence files are private and served only to people authorised for that record.
- Internal discussion is separated from anything a branch or vendor can see.
- Vendors get a private link to one job, never an account or a view of your records.
- Key actions are written to an audit history with who did them and when.
- Stock movements are append-only, so history cannot be quietly rewritten.
Credentials and connections
- Integration credentials are stored server-side and are never displayed back in the application.
- Connections have separate test and live environments, and show as not configured until a real test succeeds.
- Built connectors read only. Nothing we have built writes into your other systems.
- The one public endpoint that accepts data validates and authenticates every request.
Your data, your exit
- Every report exports as CSV, so your operational data is not locked in.
- Deletion requests can be raised and tracked in the application.
- Retention periods are configurable and agreed in your customer agreement.
What we will not claim on this page
- We hold no SOC 2, ISO 27001 or comparable certification, and we have not published a third-party penetration test.
- We publish no uptime commitment or service-level agreement. Anyone promising one at this stage would be guessing.
- Named subprocessors, hosting regions and retention defaults will be listed here once the privacy policy is finalised.
Common questions
- Where is the data hosted?
- We will name the hosting provider and region on this page as part of the privacy policy, rather than describe it loosely now.
- Can we get a security questionnaire completed?
- Yes. Send it through the contact page and we will answer it honestly, including the questions where the answer is no.
How access and records are handled
Each organisation's records are separated in the database, and people only see the branches they are assigned to. Status changes, approvals, rejections and verifications are recorded with who did them and when. We do not claim any external certification or audit at this stage; if you need a formal security review, ask us and we will tell you exactly what exists today.
