Security
What is protected today, and what is not yet.
A security page that only lists wins is marketing. This one lists the gaps too.
| Area | Status | Detail |
|---|---|---|
| Tenant isolation | Built | Each business's data is separated at the database with row-level security. |
| Role limits (owner, staff, crew) | In build | Crew will not confirm visits, change prices or widen the service area. Database-level role limits are being tightened. |
| Server-side rule enforcement | In build | Service area, weekday and window checks run on the server for every channel, not only in the browser. |
| Consent and opt-out records | Built | Consent source and time, STOP handling and quiet hours are in the messaging rules. |
| Full data export | Promised | Every plan, including attachments and history. |
| Independent audit or SOC 2 | Not held | We do not claim a certification we do not have. |
Questions, answered first
Who owns my customer data?
You do. You can export all of it on any plan and take it elsewhere.
Do you have SOC 2?
No. We do not claim any certification we do not hold.
Can a crew member change prices?
That is not allowed by design. Database-level enforcement of owner-only changes is on the build list, and the table above says so.
How do I report a security issue?
Email info@apexflowlabs.com with the subject "Security".