Trust Center Draft

Security

Security work is being built into the product from the start. This page summarizes current local controls and production controls still pending provider setup.

Current Controls

The local app includes tenant-scoped data access, role checks, session timeout behavior, audit events, security headers, request IDs, method guards, and write-rate limiting.

Data Separation

Agency records, tasks, documents, notes, support tickets, users, and audit events are designed around tenant isolation.

Uploaded PDF Lifecycle

Original ticket PDFs use private object storage and short-lived authorized download links. Files leave the normal workspace after 180 days, remain restricted to legitimate support or recovery access through day 365, and are then permanently deleted.

Operational Visibility

The app includes health, readiness, data-integrity diagnostics, backup export, recent activity, and retention sweep surfaces for owner and manager users.

Production Dependencies

Production security still requires final hosting, database, authentication, storage, email, monitoring, and payment provider configuration.

Responsible Reporting

A dedicated security contact will be published after the business domain and email routing are configured.

Launch Readiness

Before launch, the team should complete provider configuration, database policies, backup checks, account recovery testing, legal review, and pilot validation.