Security & compliance
Your plant data, protected
Security-minded design across the product — so you can focus on uptime. We state what we do today, what is on the roadmap, and what we do not claim without proof.
How we protect your data
Encryption
Production traffic is encrypted in transit with HTTPS/TLS via our edge/hosting platform. Data at rest is protected by our managed database provider using industry-standard encryption (typically AES-256 class).
Infrastructure
The app is hosted on Netlify with a managed Postgres database (not a self-run rack). Live health is published at our status page. We do not publish a contractual multi-region AWS SLA on this page.
Access control
Role-based permissions (Administrator, Team Leader, Technician, and others). Sessions are cookie-based with server-side invalidation. Optional MFA/2FA exists in the product and can be enabled for plants that require it.
Audit trail
Audit-friendly logging for important plant actions. Certification history and Equipment Card activity are designed to be time-stamped and reviewable. Export options support compliance packages.
Data ownership & retention
You own your plant data. Administrators can export Equipment Cards, people, parts, and related records (CSV/Excel and plant packages where enabled). Deletion and retention follow product privacy tools and our Privacy Policy — not indefinite vendor lock-in.
Vulnerability handling
We take security reports seriously. Contact us for responsible disclosure. We do not advertise a public bug-bounty program or annual third-party pen-test summary on this page unless documents are available on request.
Compliance status
* “Controls / process available” means product features and policies exist to support privacy programs. It is not a legal certification that every customer deployment is automatically compliant — that depends on how your organization uses the product.
Important: ITAR-controlled data
Do not upload, paste, photograph, record, store, transmit, or send ITAR-controlled technical data, drawings, files, images, specifications, or any other ITAR-controlled content into this application or to its AI assistant. This application is not authorized for ITAR-controlled data. If you are unsure whether information is ITAR-controlled, stop and contact your plant export compliance officer before uploading or sending it.
Questions about security?
Contact us for a security questionnaire, vendor review call, or responsible disclosure. Use help@ for plant support; put “Security” in the subject line for security reviews.