Loading EquipmentFlow…

Security

Last Updated: August 27, 2026

Verified safeguards EquipmentFlow uses for authentication, company-scoped access, protected storage, audit history, and responsible disclosure.

Version2.1
EffectiveAugust 27, 2026
What's ChangedRemoved unsupported certification and recovery claims and clarified verified application safeguards.
EquipmentFlow is a workflow and recordkeeping service, not legal, safety, payroll, tax, inspection, or regulatory advice. Customers should have their own policies and obligations reviewed by qualified professionals.

EquipmentFlow uses layered application and hosting safeguards to protect company records. No system eliminates all risk, and this page describes current practices without claiming a certification or guarantee.

Infrastructure & Encryption

HTTPS in Transit

Production web traffic is served over HTTPS through managed hosting. Users should confirm they are using the official EquipmentFlow domain before entering credentials or company information.

Protected Managed Storage

Operational records and uploaded files use managed database and object-storage services. Application authorization and protected file access restrict records to permitted users and workflows.

Managed Cloud Infrastructure

EquipmentFlow runs on managed Replit application, database, and storage infrastructure. Platform controls and application authorization work together to protect production services.

Access & Identity

Secure Authentication

Authentication and session management are provided through Clerk, including supported email and Google sign-in flows. EquipmentFlow does not store Clerk account passwords.

Role-Based Permissions

EquipmentFlow combines company roles with granular permissions. Owners and authorized administrators control access for administrators, supervisors, mechanics, safety managers, office staff, and employees. Server routes enforce company membership and required permissions.

QR & Barcode Access

Scanned equipment and fleet identifiers open authenticated workflows; possessing a label does not bypass company access. Invitation links and QR codes are validated separately and may expire or be revoked.

Monitoring & Recovery

Audit Logs

Supported significant actions produce timestamped audit or activity records with actor and change context. Authorized users can review relevant company history for accountability and investigation.

Managed Recovery Capabilities

EquipmentFlow relies on managed production database recovery capabilities and controlled deployment processes. Recovery capabilities reduce risk but do not guarantee that data can never be lost.

Operational Recovery

Application checkpoints, managed data recovery, and deployment controls support restoration after failures. Availability and recovery time are not guaranteed.

Data Isolation Between Companies

Authenticated requests resolve an active company membership, and supported database queries and storage reads apply company or user scope. Permission checks provide an additional boundary for sensitive actions.

Responsible Disclosure

We take security reports seriously. If you discover a potential vulnerability in EquipmentFlow, practice responsible disclosure and notify us privately before public disclosure. Please:

  • Describe the affected page, workflow, and observed behavior;
  • Avoid privacy violations, service disruption, social engineering, or destructive testing;
  • Do not access, modify, retain, or disclose data that is not yours; and
  • Allow reasonable time for investigation and remediation before disclosure.

Please do not access, modify, or delete data belonging to other users as part of your research.

Report a Security Issue

Found a vulnerability? Please reach out to our security team directly. Do not report security issues through public channels.

Report securely

Security Contact

To report a vulnerability, use the secure security report form. For account-level security concerns (compromised account, unauthorized access), contact support@equipmentflowco.com.

Have a security question that isn't covered here? Reach out to our team — we're happy to discuss our security practices with enterprise customers and prospects.