Security & reliability

Built to be trusted
with the books.

Contracts, payroll, bank lines and site evidence are the most sensitive data a building company has. Here is how the platform keeps them separate, controlled, provable and recoverable.

Your own isolated stack

Dedicated database, Redis cache, Redis queue, background workers and Telegram worker.

Backups that are proven

Daily production backups, restored into an isolated environment every week to prove they work.

Watched around the clock

A health watchdog checks the platform about every five minutes.

Access by role and by job

Role-based, job-scoped and project-specific permissions with OTP sign-in and a session guard.

Evidence you can stand behind

Private evidence files, immutable originals and append-only event histories.

Money written safely

Transactional financial writes, duplicate controls, filed-year locks and ledger-preserving migration checks.

Capability group AE

21 security and reliability capabilities.

Separation

Your company, on its own stack

  • #460Dedicated database
  • #461Dedicated Redis cache
  • #462Dedicated Redis queue
  • #463Dedicated background workers
  • #464Dedicated Telegram worker
  • #444Private evidence files
  • #449Secret separationAI integration tokens are mounted as secrets, never embedded in application code.

Access

The right people, the right jobs

  • #445Role-based data access
  • #447Session security
  • #448Web security hardening
  • #446API authorisation tests

Integrity

Money and evidence you can stand behind

  • #450Transactional financial writes
  • #451Duplicate controls
  • #452Audit trails
  • #453Document versioning
  • #454Migration guards
  • #455Ledger-preserving migration checks

Reliability

Watched, backed up and restore-tested

  • #456Health monitoringA watchdog checks the platform about every five minutes.
  • #457Daily production backup
  • #458Weekly restore verificationBackups are restored into an isolated environment every week to prove they work.
  • #459Weekly housekeeping

Controls in every module

Security is not a separate module.

Role-based and job-scoped permissions

Project managers, site supervisors and visitors see only their own jobs; workers only ever see the worker app.

OTP sign-in and a session guard

One-time-passcode sign-in, two-factor infrastructure and session protection on every account.

Filed years are locked

Once a year is filed, neither people nor agents can post into it.

Notifications never undo work

Email, Telegram and push are delivered in the background — a failed message never rolls back a business action.

Security questions

Your company runs on its own isolated stack — a dedicated database, Redis cache and queue, background workers and Telegram worker. Evidence files are private, access is role-based and job-scoped, and financial writes are transactional.

Production is backed up daily, and backups are restored into an isolated environment every week to prove they work. A health watchdog checks the platform about every five minutes.

The AI accounting team is read-only — it cannot change the ledger from chat. Receipts are reviewed before posting. The bank agent only posts when its confidence is high enough; anything else becomes a question for a person. Every agent action records its reason and confidence and can be undone, and filed years are locked.