Back to home

Data protection & security

This page describes what is actually implemented today. It is written for IT and procurement reviews, not as marketing copy. If something you need is not listed here, it is not yet in place — ask us and we will tell you honestly.

Where your data is stored

  • Database, authentication and file storage run on Supabase infrastructure hosted on AWS in the EU (eu-west-1, Ireland).
  • Uploaded files and generated analyses are stored in private buckets and tables, isolated per user account.

Access control

  • Every table enforces row-level security: a request can only read or write rows owned by the authenticated user.
  • Billing, credit and usage tables are read-only for the application client; all writes go through verified server-side functions.
  • Support access to your data is not automatic. We do not browse customer datasets as part of normal operation.

Encryption

  • All traffic between your browser and the application uses TLS (HTTPS).
  • Data at rest is encrypted by the underlying managed database and object storage.

AI processing

  • Analyses, reports and Copilot answers are generated by third-party large language models called through an AI gateway. The relevant excerpt of your data (work order rows, asset names, walkdown photos) is sent to that model for the duration of the request.
  • We do not train any model on your data, and we do not sell or share it with third parties beyond the model providers required to fulfil a request.
  • Model providers' own retention policies apply to the request payload. If your procurement process requires a named sub-processor list with contractual terms, contact us before uploading production data.

Retention and deletion

  • Uploaded files and their derived records stay until you delete them. Deleting a file removes its parsed work orders, assets and derived analyses.
  • Account deletion on request removes all associated data. Write to the contact address below and we action it manually.
  • Backups are managed by the hosting provider on its standard schedule; deleted data may persist in backups for a short period before rotation.

What is not in place yet

  • No SOC 2 or ISO 27001 certification. No signed DPA template published yet. No SSO/SAML. No customer-facing audit log export.
  • For a pilot we recommend anonymised or pseudonymised exports: asset codes instead of names, no personal data in free-text fields.

Security contact

Questions about data handling, a security review or a deletion request:

zoltan.szuri99@gmail.com