Trust & security

Built for procurement to say yes.

The facts your security review needs, stated plainly. If a question isn't answered here, ask — bring procurement to the demo.

Data residency

Australian, Sydney region

Customer data is stored in Australia (AWS ap-southeast-2). It stays onshore.

Tenant isolation

Row-level security

Each organisation's data is isolated at the database layer via row-level security — not just application logic.

Access control

Role-based, feature-level

Permissions are granted per role and per feature, so access matches your SOPs — editors edit, approvers approve, viewers view.

Encryption

Encrypted in transit

All traffic between browsers, devices and SitePilot is encrypted with TLS.

Auditability

Version history & activity logs

Plan revisions, approvals and user activity are logged and retained — your audit trail keeps itself.

Infrastructure

AWS + Vercel, monitored

Hosted on AWS and Vercel infrastructure with error and performance monitoring via Sentry.

Public viewers

Read-only by design

Published plan links are read-only. Viewers can't touch plan data — there's no auth surface to attack because there's no auth.

Backups

Nothing overwritten

Version history is append-only; archived projects retain full plan and history for retrieval.

Disclosure

Responsible disclosure

Found something? Reach out to your account manager — we take reports seriously and respond quickly.

Enterprise

SSO for enterprise agreements: single sign-on is available on Portfolio-tier agreements — talk to us about your identity provider, user onboarding and custom organisational controls.

Send us the security questionnaire.

We answer procurement reviews directly and quickly — or walk your IT team through it live.

Book a live demo