Compliance & Security Overview
This page is maintained by Compliance Desk to answer common security and privacy questions about the platform. It is app-owner maintained content, not an independent certification.
Access and authentication
Portal access requires an authenticated account with email and password or Google sign-in. Administrative capabilities are granted through a separate server-side role table and are never inferred from client-side storage. Subcontractor uploads use single-purpose, expiring links rather than shared accounts.
Tenant isolation
Every roster record, document and audit entry is scoped to the General Contractor tenant that owns it, and isolation is enforced at the database layer with row-level security rather than only in application code.
Document storage
Uploaded certificates and W-9s are written to a private storage bucket that is not publicly listable. Files are organized per tenant and per subcontractor, and reads are authorized against the same tenant rules that protect the database records.
Audit trail
Document uploads, approvals and rejections, status overrides, reminder activity and billing portal openings are recorded in an activity log with actor and timestamp, and can be searched, filtered by date, and exported to CSV for audits.
Data handling and retention
See the Privacy Policy for what we collect, which service providers process it, and how long records are kept.
Shared responsibility
We provide the tracking, storage and reminder infrastructure. General Contractors remain responsible for the accuracy of roster data, for verifying policies with licensed insurance agents, for setting their own site-access rules, and for meeting the legal requirements of their jurisdiction and contracts. Subcontractors are responsible for submitting authentic, current documents.
Reporting a security concern
If you believe you have found a vulnerability or a data-handling problem, contact your account administrator so it can be routed to us promptly. Please do not test against other tenants' data.