Skip to content

Security & Reliability

Source: Master Spec v2.0, §19.

  • Encrypt network traffic and sensitive local/server data.
  • Never store credentials or sensitive data as plain text.
  • Enforce authorization server-side, not only in the UI.
  • Preserve estimates and audit attribution when a user is deactivated.
  • Retain active estimates, versions, revisions, and history indefinitely unless deleted under policy.
  • Trash retention: 30 days.
  • Perform encrypted automatic backups; test restoration periodically — a backup is not accepted until restoration succeeds.
  • Maintain separate development, test/staging, and production environments.
  • Record actionable application and synchronization errors without exposing customer data unnecessarily.