Security
Data handling the way a service network expects it.
Customer records, contract details, technician movements and unit histories are handled with a plain, defensible posture - no dressed-up compliance claims.
What is stored
Three data classes, three treatment rules.
Customer data
Name, contact and address linked to a unit and to a contract. Retained for the life of the contract plus one year, then archived and irreversibly anonymised.
Product and contract data
Model, serial, install date, contract terms and service events. Retained for the life of the unit inside the engine, with export on demand.
Technician data
Roster, skills, working hours and route positions. Location signals are stored only as long as they are needed for active dispatch and route-load balancing.
How it is protected
Plain protections, applied by default.
Encryption in transit
All traffic to and from the engine is served over TLS 1.2 or higher. Internal service-to-service traffic is encrypted on the same standard.
Encryption at rest
Databases, object stores and backups are encrypted at rest. Backup encryption keys are managed separately from primary keys.
Role-based access
Dispatcher, technician, brand admin and read-only observer are separate roles. The technician app never sees other technicians' contract data.
Audit trails
Every contract amendment, alert override, assignment change and close-out event is logged with actor, timestamp and reason.
Compliance posture
Stated honestly, no dressed-up claims.
- Data-processing agreements available on request for brand and service-company deployments.
- GDPR-style access, correction and deletion requests are handled via a documented workflow.
- Formal ISO/SOC certifications are not held today. We are candid about the roadmap rather than claiming badges that do not apply.
- Sub-processors used for infrastructure and email delivery are listed on request.
