Plain-English summary of encryption, tenant isolation, backups, access controls, and who we share data with. Nothing here is legal boilerplate — this is what's actually true today.
All traffic between your browser and PowerPCS is encrypted in transit via HTTPS (TLS), including a valid, auto-renewing SSL certificate. Passwords are never stored in plain text — they're hashed using industry-standard one-way hashing, so even we can't see them.
PowerPCS is multi-tenant: many organizations use the same system, but your data is walled off from everyone else's. Every record — a position, an incumbent, a report — belongs to exactly one team, and the app automatically limits you to your own team's records on every request. Keeping tenants separated is a first-class priority: the data-access paths are audited specifically for it, and we treat any cross-tenant exposure as a top-severity bug we fix immediately.
Your data, recoverable by you. Every night we save a CSV snapshot of your positions, incumbents, and funding — including their change history — that you can download anytime from Setup → Backups. We keep the last seven daily snapshots, then one per week for about a month, one per month for a year, and one per year after that. If an import goes wrong or a change needs undoing, you can pull a specific past day's data and re-import it yourself — no support ticket, no waiting.
Off-site database backup. Every night your entire database is copied to separate cloud storage, encrypted in transit and kept apart from the server it came from. Backups are retained on a rolling schedule — daily, then weekly, monthly, and yearly — so a point-in-time copy exists going back years. These are tested, not assumed: we download the latest off-site backup and rebuild it into a working database, and the restored data matches row for row.
Whole-system disaster recovery. The whole server — application and database — is also snapshotted daily, so a lost server can be rebuilt from scratch, not just the data. We've run that drill too: spun up a new server from a snapshot and confirmed everything came back intact.
Two-factor authentication (2FA) is available on every account. Within a team, access is role-based — Administrator, Editor, Read Only, and a salary-blind Read Only that hides every pay and budget figure — so you control who can view or change what, right down to compensation.
We share data only with the service providers PowerPCS runs on, each bound to protect it appropriately. We don't sell data or share it with anyone else.
| Provider | Purpose |
|---|---|
| Stripe | Payment processing and billing |
| DigitalOcean | Application hosting and database infrastructure |
| Sentry | Error monitoring and diagnostics |
| Resend | Transactional email delivery (verification, password reset, notifications) |
If you have a security question, need more detail for a vendor review, or want to report a potential vulnerability, reach out through the in-app Support page (once registered) or email us at support@infisoft.com — we reply within 24-48 hours.
Start a free trial — no card required. And as always, our no-hassle promise.