Built for procurement to say yes.
The facts your security review needs, stated plainly. If a question isn't answered here, ask — bring procurement to the demo.
Australian, Sydney region
Customer data is stored in Australia (AWS ap-southeast-2). It stays onshore.
Row-level security
Each organisation's data is isolated at the database layer via row-level security — not just application logic.
Role-based, feature-level
Permissions are granted per role and per feature, so access matches your SOPs — editors edit, approvers approve, viewers view.
Encrypted in transit
All traffic between browsers, devices and SitePilot is encrypted with TLS.
Version history & activity logs
Plan revisions, approvals and user activity are logged and retained — your audit trail keeps itself.
AWS + Vercel, monitored
Hosted on AWS and Vercel infrastructure with error and performance monitoring via Sentry.
Read-only by design
Published plan links are read-only. Viewers can't touch plan data — there's no auth surface to attack because there's no auth.
Nothing overwritten
Version history is append-only; archived projects retain full plan and history for retrieval.
Responsible disclosure
Found something? Reach out to your account manager — we take reports seriously and respond quickly.
SSO for enterprise agreements: single sign-on is available on Portfolio-tier agreements — talk to us about your identity provider, user onboarding and custom organisational controls.
Send us the security questionnaire.
We answer procurement reviews directly and quickly — or walk your IT team through it live.