Security

What is protected today, and what is not yet.

A security page that only lists wins is marketing. This one lists the gaps too.

Security status by area
AreaStatusDetail
Tenant isolationBuiltEach business's data is separated at the database with row-level security.
Role limits (owner, staff, crew)In buildCrew will not confirm visits, change prices or widen the service area. Database-level role limits are being tightened.
Server-side rule enforcementIn buildService area, weekday and window checks run on the server for every channel, not only in the browser.
Consent and opt-out recordsBuiltConsent source and time, STOP handling and quiet hours are in the messaging rules.
Full data exportPromisedEvery plan, including attachments and history.
Independent audit or SOC 2Not heldWe do not claim a certification we do not have.

Questions, answered first

Who owns my customer data?
You do. You can export all of it on any plan and take it elsewhere.
Do you have SOC 2?
No. We do not claim any certification we do not hold.
Can a crew member change prices?
That is not allowed by design. Database-level enforcement of owner-only changes is on the build list, and the table above says so.
How do I report a security issue?
Email info@apexflowlabs.com with the subject "Security".