Security & Reliability
Source: Master Spec v2.0, §19.
- Encrypt network traffic and sensitive local/server data.
- Never store credentials or sensitive data as plain text.
- Enforce authorization server-side, not only in the UI.
- Preserve estimates and audit attribution when a user is deactivated.
- Retain active estimates, versions, revisions, and history indefinitely unless deleted under policy.
- Trash retention: 30 days.
- Perform encrypted automatic backups; test restoration periodically — a backup is not accepted until restoration succeeds.
- Maintain separate development, test/staging, and production environments.
- Record actionable application and synchronization errors without exposing customer data unnecessarily.