Security practices
Current safeguards, shared responsibilities, and the channel for reporting a potential vulnerability.
Access protection
- Authentication with protected sessions and hashed password storage.
- Roles and permissions that restrict administrative operations.
- Logical organization separation in multi-company features.
- Production secrets managed outside source code.
Operational protection
- Transport encryption through HTTPS.
- Technical and audit logs for investigating relevant activity.
- Input validation and authorization checks for sensitive operations.
- Specialized providers for infrastructure, databases, email, storage, and artificial intelligence.
Shared responsibility
Each customer must manage its users, permissions, devices, content, and authorizations. We recommend unique passwords, periodic access reviews, and immediate reporting of suspicious activity.
Responsible reporting
If you believe you found a vulnerability, email trends172tech@gmail.com with the subject “Security”. Include the affected service, reproduction steps, and potential impact. Do not access another person’s data, disrupt the service, or publish information before we can investigate.
Assurance status
We maintain a continuous-improvement program and document controls and evidence. We do not currently claim SOC 2, ISO 27001, HIPAA, or other certifications that have not been formally audited. Additional requirements are evaluated by contract.