Company data isolation
Operational records are scoped to the signed-in company. Roles control administration, supervision, field work and read-only access.
TRUST CENTRE
PreStartPilot separates company data, records important operational changes and protects access from the browser through to the database.

Operational records are scoped to the signed-in company. Roles control administration, supervision, field work and read-only access.
Passwords are strongly hashed. Sessions use signed, HTTP-only cookies, and every new workspace starts with authenticator MFA required. A restricted first-login setup grants no workspace access until the authenticator code is verified and recovery codes are issued. Distributed throttles protect sensitive sign-in, recovery and bulk-invitation actions from repeated abuse. Company identity can use OpenID Connect with PKCE or signed SAML 2.0 assertions with Redis-backed replay protection. The MFA, user access and SSO guide covers the administrator and team-member steps.
Inspection submissions, account changes and other sensitive actions generate timestamped audit events for company review.
HTTPS, private service networking, restricted database access, persistent evidence storage and verified recovery procedures protect operational data.
Company API credentials are revocable, stored as hashes and scoped to the organisation that created them.
Security concerns can be reported privately through the PreStartPilot contact page for prompt review.