TRADESCRAFT

Security

Last reviewed 10 September 2026

Trades businesses run on this software. We use business-level access controls, account permissions and sign-in checks to protect their records.

Your data is yours, and only yours

Access to business records is checked against business membership and permissions. Staff, customers and subcontractors receive access to the records their roles allow. Administrators manage those permissions.

Where your data lives

Your operational data and uploaded files are hosted with Supabase in Japan. The provider encrypts stored data, and network connections use TLS. Our sub-processor list identifies the services involved.

How you sign in

We never see or store your password. Sign-in is handled by an industry-standard identity provider that hashes and salts credentials.

Two-factor authentication using any standard authenticator app (Google Authenticator, 1Password, Authy, etc.) is available for every account. Turn it on from Settings → Security.

For a phishing-resistant option you can add a passkey - Face ID, Touch ID, Windows Hello or a hardware security key - either as a second factor or for one-tap passwordless sign-in. Set it up from the same Settings → Security screen.

Audit trail

Administrators can review recorded account activity and changes in the Audit log. Entries identify the action, time and actor where available. Sensitive values are redacted, and the detail recorded depends on the event.

Backups and recovery

Our recovery procedures cover restoring the managed database and checking the application afterward. Available restore points and recovery time depend on the backups available and the scope of an incident. Contact security@tradescraft.app for current recovery arrangements before relying on a specific retention period or recovery deadline.

This page does not commit to a fixed backup-retention period, recovery point objective (RPO) or recovery time objective (RTO). A backup-copy deletion window is separate from how far back a working database can be restored.

Your own controls

  • Admins can export business records as a machine-readable file without contacting us.
  • Members can leave a business, and admins can request deletion of the business through the self-service controls at Settings → Security → Your data. Retention requirements and backup copies are described in our privacy policy.
  • Granular per-event notification preferences let people control what they receive at Settings → My Notifications.

What we use third parties for

Card payments are handled by a PCI-DSS-compliant payment processor; we never see or store card numbers. Customer-facing email is delivered through a specialist provider under contract (customer-facing SMS is coming soon). Each provider's privacy and security disclosures apply to their own infrastructure - see our privacy policy for the current list.

Reporting a vulnerability

If you find something, please tell us before telling anyone else. Email security@tradescraft.app with a reproduction. We aim to acknowledge within 48 hours and ship fixes for valid high-severity issues within 7 days. We don't run a paid bug-bounty program yet, but we're happy to credit you publicly if you'd like.

Incident notification

If a security incident is likely to result in serious harm to anyone's personal information, we'll notify affected users and the relevant regulator under the applicable scheme (the Notifiable Data Breaches scheme in Australia, the equivalent obligations under GDPR where it applies, and comparable requirements in New Zealand).