Security & reliability
Built to be trusted
with the books.
Contracts, payroll, bank lines and site evidence are the most sensitive data a building company has. Here is how the platform keeps them separate, controlled, provable and recoverable.
Your own isolated stack
Dedicated database, Redis cache, Redis queue, background workers and Telegram worker.
Backups that are proven
Daily production backups, restored into an isolated environment every week to prove they work.
Watched around the clock
A health watchdog checks the platform about every five minutes.
Access by role and by job
Role-based, job-scoped and project-specific permissions with OTP sign-in and a session guard.
Evidence you can stand behind
Private evidence files, immutable originals and append-only event histories.
Money written safely
Transactional financial writes, duplicate controls, filed-year locks and ledger-preserving migration checks.
Capability group AE
21 security and reliability capabilities.
Separation
Your company, on its own stack
- #460Dedicated database
- #461Dedicated Redis cache
- #462Dedicated Redis queue
- #463Dedicated background workers
- #464Dedicated Telegram worker
- #444Private evidence files
- #449Secret separationAI integration tokens are mounted as secrets, never embedded in application code.
Access
The right people, the right jobs
- #445Role-based data access
- #447Session security
- #448Web security hardening
- #446API authorisation tests
Integrity
Money and evidence you can stand behind
- #450Transactional financial writes
- #451Duplicate controls
- #452Audit trails
- #453Document versioning
- #454Migration guards
- #455Ledger-preserving migration checks
Reliability
Watched, backed up and restore-tested
- #456Health monitoringA watchdog checks the platform about every five minutes.
- #457Daily production backup
- #458Weekly restore verificationBackups are restored into an isolated environment every week to prove they work.
- #459Weekly housekeeping
Controls in every module
Security is not a separate module.
Role-based and job-scoped permissions
Project managers, site supervisors and visitors see only their own jobs; workers only ever see the worker app.
OTP sign-in and a session guard
One-time-passcode sign-in, two-factor infrastructure and session protection on every account.
Filed years are locked
Once a year is filed, neither people nor agents can post into it.
Notifications never undo work
Email, Telegram and push are delivered in the background — a failed message never rolls back a business action.
Security questions
Your company runs on its own isolated stack — a dedicated database, Redis cache and queue, background workers and Telegram worker. Evidence files are private, access is role-based and job-scoped, and financial writes are transactional.
Production is backed up daily, and backups are restored into an isolated environment every week to prove they work. A health watchdog checks the platform about every five minutes.
The AI accounting team is read-only — it cannot change the ledger from chat. Receipts are reviewed before posting. The bank agent only posts when its confidence is high enough; anything else becomes a question for a person. Every agent action records its reason and confidence and can be undone, and filed years are locked.