Legal

Security

Effective August 25, 2026
This page covers how we protect your data day to day. Short version: HTTPS everywhere, an encrypted database, one isolated workspace per shop, point-in-time recovery, and least-privilege access held by one operator. We describe only controls we actually run, and we say where we fall short. Report a vulnerability to sean@trusspath.com — we aim to acknowledge within 2 business days.

1. Data isolation

Every TrussPath customer lives inside a workspace (also called a tenant). Every row in the database — customer, job, estimate, invoice, employee, time entry — is tagged with atenant_id column, and every API request checks that column against your session before returning or writing anything. Cross-tenant queries are blocked at the application layer.

2. Encryption

3. Authentication

4. Payments

TrussPath uses Stripe for payment processing. We do not store credit card numbers, CVCs, or bank account numbers on our servers. Stripe is PCI DSS Level 1 certified.

5. Infrastructure

6. Backups and disaster recovery

Neon holds a continuous write-ahead log for the production database, so we can restore to any point inside our plan retention window rather than to the last nightly snapshot. Backups are encrypted at rest by Neon. Restoring to a fresh branch is a routine Neon operation, but we have not yet run and documented a full restore drill; that is tracked as an open item rather than presented as a tested capability.

7. Access controls

8. Monitoring and incident response

Application errors, request logs, and uptime are captured by our hosting platform and reviewed when we deploy or when something is reported. We do not yet run automated alerting on authentication anomalies. If we detect or are notified of a security incident, we'll:

9. Vulnerability reporting

If you believe you've found a security vulnerability, please email sean@trusspath.com with a description and steps to reproduce. We'll acknowledge within two business days and work with you in good faith to fix and, where appropriate, credit you. Please don't test against real customer data — we'll set up a sandbox on request.

10. What we ask of you

Good security is a shared responsibility. Please:

11. Contact

Security questions or reports: sean@trusspath.com. TrussPath, LLC — Denver, Colorado.

Questions? Email sean@trusspath.com.