Security

Your customers’ details are not ours to be casual with.

Names, phone numbers, registrations and payment records sit in this product. Here is what protects them, described as what it does rather than as a badge.

One workspace cannot see another

Every record belongs to a garage, and the database refuses to answer a question that does not say which garage is asking. It is not a filter someone has to remember to add, a query without a workspace fails rather than returning everyone’s rows.

Your sign-in never touches the browser

The credential that authorises requests is held server-side in a cookie JavaScript cannot read. A malicious script on the page has nothing to steal, and sessions expire on their own.

Sign-in is rate limited twice over

By address and by email. One machine cannot work through a password list, and a spread-out attempt against many addresses is caught by the second limit rather than slipping under the first.

Permissions are checked per record

Not once per screen. A bulk action checks every row it touches, so a selection can never be used to reach something the person could not open on its own.

An append-only record of changes

Who changed what, and when, across the records that matter, written automatically rather than when someone remembers, and never editable afterwards.

Approvals prove who answered

Work above a threshold you set asks the customer to confirm the phone number on file before it can be approved, and stops accepting guesses after five wrong answers.

What we have not done

The honest list.

Every security page says what a product does well. This is the other half, because you are going to find out eventually and it should be from us.

  • Independent penetration testing has not been carried out yet.
  • We are not SOC 2 or ISO 27001 certified, and will say so until we are.
  • Payments currently run through a sandbox provider; no live card data passes through the product.
  • Data is retained indefinitely today, a retention policy is on the roadmap, not shipped.

Found something? Tell us.

Report a vulnerability and we will respond within two working days. No legal threats, no hoops, we would rather hear it from you than from a customer.

Get in touch