TRUST CENTRE

Security built into every pre-start.

PreStartPilot separates company data, records important operational changes and protects access from the browser through to the database.

Secure by designIdentity, access and audit controls

Company data isolation

Operational records are scoped to the signed-in company. Roles control administration, supervision, field work and read-only access.

Secure authentication

Passwords are strongly hashed. Sessions use signed, HTTP-only cookies, and every new workspace starts with authenticator MFA required. A restricted first-login setup grants no workspace access until the authenticator code is verified and recovery codes are issued. Distributed throttles protect sensitive sign-in, recovery and bulk-invitation actions from repeated abuse. Company identity can use OpenID Connect with PKCE or signed SAML 2.0 assertions with Redis-backed replay protection. The MFA, user access and SSO guide covers the administrator and team-member steps.

Auditability

Inspection submissions, account changes and other sensitive actions generate timestamped audit events for company review.

Protected infrastructure

HTTPS, private service networking, restricted database access, persistent evidence storage and verified recovery procedures protect operational data.

API security

Company API credentials are revocable, stored as hashes and scoped to the organisation that created them.

Responsible disclosure

Security concerns can be reported privately through the PreStartPilot contact page for prompt review.