Every company’s data is isolated at the database
Each company (“tenant”) is separated inside the database by row-level security — rules enforced by PostgreSQL itself, not just by the app. A query can only ever return rows for a company you are a verified member of; the separation does not depend on the interface behaving correctly.
This is adversarially tested: we run attack simulations that attempt cross-company reads and writes, member self-promotion, and manager-permission abuse. As of the 19 August 2026 review, every one was blocked.
Encrypted in transit and at rest
All traffic runs over HTTPS/TLS. Data at rest is encrypted by our database and storage provider (Supabase, on AWS). We never store your password — authentication is handled by our provider and passwords are kept only as salted hashes.
We never touch card numbers
Your subscription is billed through Stripe; your clients pay your invoices through your own Stripe account. Card data is handled by Stripe (a PCI-DSS Level 1 provider) — Track & Bill never sees, stores, or processes card numbers, yours or your clients’.
Least-privilege access, MFA on admin systems
Administrative access to the systems that run Track & Bill is limited to the operator and protected by multi-factor authentication. Application secrets (API keys, tokens) live in server-side secret stores, never in the app you download or in our code.
Your data is yours — export or delete it anytime
You can export everything you have entered — clients, time, mileage, expenses, invoices, the retainer ledger — with one click, on every plan, at any time, including during the trial and after you cancel. Account deletion is available in the app with a typed confirmation and removes your data from the live system.
If we ever shut Track & Bill down, you get at least 90 days’ notice and your full export before anything is removed.
Changes are tested before they ship
Code changes are written with their tests, run through an automated test suite that must pass, and deployed to a preview build for verification before they reach production. We keep a running change log, and code changes are reviewed on a weekly cadence.
Monitoring and backups
The platform is health-checked continuously and errors are logged for review. The database is backed up by our provider with point-in-time recovery, so data can be restored if something goes wrong.