Security overview
Current safeguards
- Passwordless email sign-in for invited contractor users.
- Database row-level security that checks organization membership before returning client records.
- Role-based access for owners, managers, sales users, viewers, and billing users.
- Private project-file storage policies when file collection is enabled.
- Encrypted HTTPS connections, browser security headers, input limits, and server-side validation.
- Platform-owner access limited to Jordan and Devan for onboarding, support, security, and account administration.
Shared responsibility
Contractors must protect their email accounts and devices, invite only people who need access, assign the least privilege required, and remove former team members promptly. ScopeBriefing should be told immediately if an account, device, or sign-in link may be compromised.
Data handling
The product is intended for ordinary project and contact information. Do not collect Social Security numbers, payment-card details, medical records, government identification, passwords, or other highly sensitive information through estimator questions or notes.
Report a vulnerability
Send a clear description to both owner addresses. Do not access, alter, download, or retain another person’s data; disrupt service; use automated high-volume testing; or publish a vulnerability before we have had a reasonable opportunity to investigate. We will acknowledge good-faith reports and coordinate remediation.
Incident response
We investigate suspected incidents, contain affected access, preserve relevant records, correct the cause, and notify contractors or individuals when required. Contractors are responsible for giving ScopeBriefing an up-to-date security contact.