Skip to content
AegisSpan
SECURITY & TRUST

Specific controls. Clear limits.

These are implemented application measures, not a certification or a guarantee that every risk has been eliminated.

Organization and role access

Application requests use the signed-in member’s organization and server-side permissions. Public self-signup is closed. New accounts require a valid invitation matching their email address, and new workspaces require an existing active owner. Owners, admins, operations managers, crew leaders and technicians have different access. Field job access follows relevant assignments.

Accounts and sessions

Passwords are hashed using scrypt. Session tokens are stored as hashes. Production HTTPS session cookies use Secure, HttpOnly and SameSite settings, with idle and absolute expiration. Password resets invalidate existing sessions.

Private files and proposal links

Record uploads use private object storage. Application file downloads check authorization. Public proposal links grant access to that specific proposal to anyone holding the link, so share them only with intended reviewers.

Request and file validation

The application uses bound SQL values, input validation, same-origin checks for authenticated changes, and upload size/type/signature checks. Authentication and selected public actions have rate limits. These checks do not constitute malware scanning.

Recorded activity

Account audit records, operational activity and proposal events retain recorded actions, actors and timestamps. Application-level history is append-only. This is not a claim of independently certified tamper-proof storage.

Data collection

Product usage events store event names, opaque record/organization identifiers and timestamps rather than copying note text or file contents. The public site records visit/CTA events with a per-tab identifier, and stores the contact details submitted in the access form.

Current beta limitations

We do not claim SOC 2, ISO certification, an independent penetration test, regulatory compliance certification, offline synchronization, or automated malware scanning. Backup recovery and production email delivery need deployment-specific verification. The platform does not make safety approvals or engineering determinations.

Before sharing sensitive information

Use the access request to discuss your organization’s requirements before adding sensitive records. Do not include passwords, access codes or confidential incident details in that public form.

CONTROLLED BETA

See how your work fits together.

Tell us about your company. We’ll review your request and contact you at your work email to arrange a walkthrough of the current product.

Requesting a demo does not create an account or start a paid subscription. We use these details to review your request and contact you about AegisSpan. No payment information is collected here.

Request a demo

Primary services · choose at least one

Your request is saved only after the confirmation appears. Already have access? Sign in.