What happens to your operation's data
Written plainly, because the person asking is usually the one signing. If something here is not enough for your policy, write to us and ask.
Each organization is separated
Every record belongs to one organization and every read and write is scoped to it. Branch users see only the branches they are assigned. The application enforces this on every route, and the database enforces it again underneath — one forgotten filter is not enough to cross the line.
Who can do what
Roles are granular and scoped to branches, not just to the organization. Administrative actions require a second factor, and support access to your workspace is time-boxed and written to an audit log you can read.
Records you can prove
Inspection and checklist completions are chained with a cryptographic hash, so a record cannot be quietly altered or back-dated after the fact. An exported packet can be verified from its link by anyone you send it to, including a regulator.
In transit and at rest
All traffic is served over TLS. Credentials you give us for third-party systems are encrypted with a key held outside the database, so a copy of the database alone does not expose them.
Backups and getting your data out
The database and your uploaded files are backed up on a daily schedule. You can export your own records at any time without asking us — your operating history is yours, and nothing here is designed to make leaving difficult.
What we have not done yet
We hold no third-party security certification today, and we would rather say so than imply otherwise. Ask us for the current picture before you make it a condition, and we will answer precisely.
Found something? Tell us
If you believe you have found a security problem, write to us before disclosing it publicly and we will work with you on it. We would much rather hear it from you first.