Platform Security
How We Protect Your Data
Plain-English answers to how your financial data is stored, who can access it, and what we ask of you.
1. How your data is stored
All platform data is stored in Supabase, a hosted database service running on Amazon Web Services (AWS). Your data lives on their infrastructure — not on a server we own or manage directly.
In transit: Every connection between your browser, our servers, and the database is encrypted using TLS 1.2 or higher. There is no unencrypted HTTP fallback. You will always see HTTPS in your browser.
At rest: All data stored in Supabase Postgres is encrypted at the infrastructure level using AES-256. This includes database records, backups, and file storage.
Compliance: Supabase is SOC 2 Type II certified. AWS infrastructure (which Supabase runs on) holds ISO 27001, SOC 1/2/3, and PCI DSS compliant certifications. These certifications are maintained and audited by independent third parties.
Financial figures — Cost to Complete entries, WIP positions, invoice amounts — are never saved in your browser's storage.
2. Who can see your data
Other users cannot see your data. The database enforces Row Level Security (RLS) — a rule set built directly into the database engine. A query from one user's session cannot return another user's records, even if the request is deliberately crafted to try.
Server-side operations — billing, document generation, and similar tasks — use a privileged Supabase key that is not limited by RLS. Those operations run only on our servers and are limited in code to the signed-in account's records. The key is stored only in server-side environment variables — never in browser code or source code.
We will not access your financial data except: (a) in response to a verified support request from the account owner, or (b) as required by law. This is the same model used by Procore, Sage, Buildertrend, and QuickBooks Online — every SaaS platform you use operates on it.
3. How documents are protected
Generated PDFs and Excel files — WIP exports, invoices, pay applications, change orders — are stored in private Supabase Storage buckets. They are not accessible by a public URL. You cannot guess or enumerate a document URL.
Documents are served through signed links — a time-limited, cryptographically signed link that stops working after it expires. Depending on the document, a link lasts between 15 minutes and 24 hours. Until it expires, anyone who has the link can open it, so treat download links like the documents themselves and don't forward them.
4. How your financial records are locked
Once you confirm and lock a WIP period, it cannot be edited.
Correcting a locked period takes a deliberate unlock step. Deleting a locked period, or the Cost to Complete entry it was built from, requires an extra confirmation. Every unlock and deletion is recorded in the platform's audit log with the date and the account that made it, and that log cannot be edited or deleted.
This protects against accidental overwrites and gives you a clear answer if a lender or surety company asks when a reported figure changed.
5. What we ask of you
Platform security only works if your account credentials are secure. We ask that you:
- Use a strong, unique password for this account.
- Enable two-factor authentication on your email account — your email is the key to this platform.
- Log out when you are on a shared or public device. Close the browser tab.
- Do not share your login credentials with anyone.
- If you suspect your account has been accessed without your permission, email contact@bosamcandc.com immediately.
6. How to request your data
You may request a full export of your account data at any time.
Email contact@bosamcandc.com from the email address on your account. Include your company name and what you are requesting. We will respond within 5 business days.
To request deletion of your account and all associated data, email the same address with the subject line: "Data Deletion Request." Deletion is permanent and cannot be undone.
7. How to report a security issue
If you discover a vulnerability or a potential security issue with the platform, please report it responsibly before disclosing it publicly.
Email contact@bosamcandc.com. Include a description of what you found and how to reproduce it. We will acknowledge your report within 48 hours and will work to resolve confirmed issues promptly.
In the event of a confirmed data breach affecting customer financial data, affected account owners will be notified by email within 72 hours. Notification will include what data was affected, the time window, and what is being done.