Evidence your client can trust starts with security you can verify.
SNTNL's product is proof — GPS records, timestamps, photos, reports your clients, auditors, and lawyers rely on. This page is how that proof is protected.
Encryption in transit and at rest
Traffic between your browser or the guard app and SNTNL is encrypted in transit over TLS. Data stored in our managed database and file storage is encrypted at rest by the platform that hosts it. Detailed documentation available on request for your IT review.
Role-based access, logged
Permissions are role-based across admin, supervisor, guard, and client roles, and access is enforced on the server — not merely hidden in the interface. Client users only ever reach their own sites and contracts. Changes to records carry who made them, what changed, and when.
Evidence integrity
Reports preserve the original field entry alongside any AI-polished version, so the guard's own words remain available for audit. Timestamps and GPS stamps are recorded at the moment of capture and are not editable after the fact — corrections are added as new, attributed entries rather than silent overwrites.
Backups, retention & your exit
The database is backed up automatically by our managed hosting platform, and retention is configured per customer agreement. And the policy that matters most: your data exports free, always. Leaving SNTNL never costs you your records — no export fee, no hostage period, no "contact your account manager" gate.
Subprocessors
The third-party services SNTNL relies on today, and what each one receives.
| Subprocessor | Purpose | What it receives |
|---|---|---|
| Lovable | Application hosting, build pipeline, and CDN delivery | Public website content and static assets; standard web request metadata. |
| Supabase | Database, authentication, file storage, and serverless functions | Operational records held in SNTNL — accounts, sites, shifts, reports, uploaded media — plus authentication data. |
| Postmark | Transactional email delivery | Recipient email addresses and the contents of the messages we send, such as proposals and notifications. |
| Google Analytics 4 | Website analytics on our marketing site | Pseudonymised marketing-site usage events. It is not used inside the SNTNL application. |
| GoHighLevel | Demo scheduling and CRM for inbound sales | Contact details you enter when booking a demo. It receives no guard or client operational data. |
This list reflects the vendors in use today. We will notify customers before adding a subprocessor that handles operational data, and detailed documentation on each vendor's data-handling terms is available on request.
Compliance roadmap
Stated plainly, with no badges we haven't earned.
In place today
- Encryption in transit and at rest through our hosting platform.
- Server-enforced role-based access across admin, supervisor, guard, and client roles.
- Row-level data isolation between customers in the application database.
- Change attribution on operational records — who, what, when.
- Automated database backups managed by our hosting platform.
- Free data export, always.
In progress
- Formal written security policy set and documented incident-response runbook.
- Independent third-party audit or certification: not yet held. We will not claim one before it exists.
- Customer-facing data processing agreement template.
- Published retention schedule per data category.
- Penetration test with a summary letter shareable under NDA.
For anything not listed as in place: detailed documentation available on request.
Need this for your IT or client security review? We'll answer your questionnaire directly.
Send it over and a human who knows the architecture will complete it — no portal, no runaround.