Security and records
What we do, stated plainly. If something here matters to your decision, ask us and we will confirm it in writing.
Access
- Each plant is its own workspace. Data is separated by workspace on every request.
- Roles and line access are enforced on the server. A line lead's phone never receives other lines' data.
- Passwords are stored as salted hashes. Accounts lock for a minute after five wrong passwords.
- Phones lock after 15 minutes idle. Signing out removes plant data from the phone.
- A plant admin can switch off any person's access and it takes effect immediately.
Records
- Manager notes can't be edited or deleted. Mistakes are voided with a reason and stay on record.
- Locked rotations and saved audits can't be changed. Changes to an audit's manager note keep earlier versions.
- The activity log is written by the server with server time and the signed-in user. Each entry includes a hash of the one before it, and a plant admin can verify the chain.
- Legal hold blocks every deletion until a plant admin ends it, and ending it is logged.
Your data
- You can export everything at any time. You can ask for your plant to be deleted. Deletion is final after 30 days.
- We do not sell your data and do not show ads.
- Our own staff console shows only account and usage details, not your people, notes or audits.
What we have not done yet
We have not completed an independent security audit or a compliance certification. Do not assume one. Employee names, numbers and notes are employee records: agree retention and access rules with your HR and legal teams.