Your projects. Your data. Your rules. We store as little as possible, your files can live in your own Drive, and your clients never need an account. Here’s exactly how it works.
Teams whose projects involve clients, vendors, money, and site photos — where “who saw what, and where did that file go” actually matters.
The safest data is the data we never hold. We keep what’s needed to run the service — and nothing else.
Start with 10 GB on us, or connect a free Google Drive and every future upload lands in your cloud instead. The switch is binary, and reversible.
Magic links let clients and vendors join without an account — and each link is tightly scoped so it can only ever do one thing.
Clients and vendors upload from devices you don’t control. We treat every upload as untrusted until it proves what it is.
A photo from a job site or a listing carries GPS coordinates by default. We strip that before it ever leaves the browser — so a shared thread can’t give away an address or a vacant property.
The plumbing that holds it all up — for the people who want the specifics.
HTTPS everywhere with HSTS, a strict CSP on the authenticated app, and modern TLS only.
bcrypt password hashing, optional TOTP two-factor, server-side sessions (never JWTs), 8h idle / 30d absolute, and CSRF tokens on every state-changing form.
Every query is filtered by your active workspace, with owner / admin / member role gating on sensitive actions.
Outbound HMAC-SHA256 signing, inbound shared-secret checks with rate limiting, and idempotency keys on every delivery.
Twilio signatures checked on every inbound SMS; the IMAP poller authenticates your mailbox; routing keyed on workspace + project, never user-controlled IDs.
Every workspace-mutating action records who, what, and when — available to workspace owners on request.
Found a vulnerability? Email with the subject Security report. We acknowledge within 2 business days and fix high-severity issues before public disclosure. We’re a small team — please don’t run automated scans against production; we’ll happily provide a staging environment if you ask.
Honest about what isn’t done yet:
Need one of these before signing? Talk to us.
Have a security question before you put a deal on it? Start free, or reach out — we answer fast.
See plans