Plain-English summary of encryption, tenant isolation, backups, access controls, and who we share data with. Nothing here is legal boilerplate — this is what's actually true today.
All traffic between your browser and PowerPCS is encrypted in transit via HTTPS (TLS), including a valid, auto-renewing SSL certificate. Passwords are never stored in plain text — they're hashed using industry-standard one-way hashing, so even we can't see them.
PowerPCS is multi-tenant: every customer's data — positions, incumbents, reports, everything — is scoped to their own team at the database query level, automatically, on every request. One customer's data is never visible to another. This isolation was audited line-by-line across every data-access path in the application, not just spot-checked.
Production is backed up daily and retained for roughly a week. This isn't a theoretical safeguard — we've run a full restore drill: spun up a new server from a backup, confirmed the data came back intact, and verified the whole recovery process actually works end to end.
Two-factor authentication (2FA) is available on every account. Within a team, access is role-based — Administrator, Editor, or Read Only — so you control who can view or change what.
We share data only with the service providers PowerPCS runs on, each bound to protect it appropriately. We don't sell data or share it with anyone else.
| Provider | Purpose |
|---|---|
| Stripe | Payment processing and billing |
| DigitalOcean | Application hosting and database infrastructure |
| Sentry | Error monitoring and diagnostics |
| Resend | Transactional email delivery (verification, password reset, notifications) |
If you have a security question, need more detail for a vendor review, or want to report a potential vulnerability, reach out through the in-app Support page (once registered) or contact us directly — we reply within 24-48 hours.
Start a free trial — no card required. And as always, our no-hassle promise.