Organization and role access
Application requests use the signed-in member’s organization and server-side permissions. Public self-signup is closed. New accounts require a valid invitation matching their email address, and new workspaces require an existing active owner. Owners, admins, operations managers, crew leaders and technicians have different access. Field job access follows relevant assignments.
Accounts and sessions
Passwords are hashed using scrypt. Session tokens are stored as hashes. Production HTTPS session cookies use Secure, HttpOnly and SameSite settings, with idle and absolute expiration. Password resets invalidate existing sessions.
Private files and proposal links
Record uploads use private object storage. Application file downloads check authorization. Public proposal links grant access to that specific proposal to anyone holding the link, so share them only with intended reviewers.
Request and file validation
The application uses bound SQL values, input validation, same-origin checks for authenticated changes, and upload size/type/signature checks. Authentication and selected public actions have rate limits. These checks do not constitute malware scanning.
Recorded activity
Account audit records, operational activity and proposal events retain recorded actions, actors and timestamps. Application-level history is append-only. This is not a claim of independently certified tamper-proof storage.
Data collection
Product usage events store event names, opaque record/organization identifiers and timestamps rather than copying note text or file contents. The public site records visit/CTA events with a per-tab identifier, and stores the contact details submitted in the access form.
Current beta limitations
We do not claim SOC 2, ISO certification, an independent penetration test, regulatory compliance certification, offline synchronization, or automated malware scanning. Backup recovery and production email delivery need deployment-specific verification. The platform does not make safety approvals or engineering determinations.
Before sharing sensitive information
Use the access request to discuss your organization’s requirements before adding sensitive records. Do not include passwords, access codes or confidential incident details in that public form.