Tenant isolation in the database
Every tenant query runs under a restricted Postgres role with row-level security, so one agency can never read another's records — even if a query forgets a filter.
Security
A plain-language summary. The full security model, data map, threat model, and incident process are maintained with the source code.
Every tenant query runs under a restricted Postgres role with row-level security, so one agency can never read another's records — even if a query forgets a filter.
Access and refresh tokens are sealed with AES-256-GCM, never sent to the browser, and deleted on disconnect.
Approval, portal, intake, and report links are opaque, hashed at rest, expire on schedule, and can be revoked at any time.
Approvals, schedule changes, publishes, replies, exports, and settings changes are logged with actor, time, and correlation ID.
Nine organization roles and optional per-client restriction. API keys are scoped, hashed, expiring, and start in dry-run mode.
No compliance certification is claimed. We publish our data map, threat model, and incident process instead.
Report a vulnerability to the support address in the footer. We acknowledge within two business days.