Trust Center Draft
Security
Security work is being built into the product from the start. This page summarizes current local controls and production controls still pending provider setup.
Current Controls
The local app includes tenant-scoped data access, role checks, session timeout behavior, audit events, security headers, request IDs, method guards, and write-rate limiting.
Data Separation
Agency records, tasks, documents, notes, support tickets, users, and audit events are designed around tenant isolation.
Uploaded PDF Lifecycle
Original ticket PDFs use private object storage and short-lived authorized download links. Files leave the normal workspace after 180 days, remain restricted to legitimate support or recovery access through day 365, and are then permanently deleted.
Operational Visibility
The app includes health, readiness, data-integrity diagnostics, backup export, recent activity, and retention sweep surfaces for owner and manager users.
Production Dependencies
Production security still requires final hosting, database, authentication, storage, email, monitoring, and payment provider configuration.
Responsible Reporting
A dedicated security contact will be published after the business domain and email routing are configured.
Launch Readiness
Before launch, the team should complete provider configuration, database policies, backup checks, account recovery testing, legal review, and pilot validation.