Security
Last Updated: August 27, 2026Verified safeguards EquipmentFlow uses for authentication, company-scoped access, protected storage, audit history, and responsible disclosure.
EquipmentFlow uses layered application and hosting safeguards to protect company records. No system eliminates all risk, and this page describes current practices without claiming a certification or guarantee.
Infrastructure & Encryption
HTTPS in Transit
Production web traffic is served over HTTPS through managed hosting. Users should confirm they are using the official EquipmentFlow domain before entering credentials or company information.
Protected Managed Storage
Operational records and uploaded files use managed database and object-storage services. Application authorization and protected file access restrict records to permitted users and workflows.
Managed Cloud Infrastructure
EquipmentFlow runs on managed Replit application, database, and storage infrastructure. Platform controls and application authorization work together to protect production services.
Access & Identity
Secure Authentication
Authentication and session management are provided through Clerk, including supported email and Google sign-in flows. EquipmentFlow does not store Clerk account passwords.
Role-Based Permissions
EquipmentFlow combines company roles with granular permissions. Owners and authorized administrators control access for administrators, supervisors, mechanics, safety managers, office staff, and employees. Server routes enforce company membership and required permissions.
QR & Barcode Access
Scanned equipment and fleet identifiers open authenticated workflows; possessing a label does not bypass company access. Invitation links and QR codes are validated separately and may expire or be revoked.
Monitoring & Recovery
Audit Logs
Supported significant actions produce timestamped audit or activity records with actor and change context. Authorized users can review relevant company history for accountability and investigation.
Managed Recovery Capabilities
EquipmentFlow relies on managed production database recovery capabilities and controlled deployment processes. Recovery capabilities reduce risk but do not guarantee that data can never be lost.
Operational Recovery
Application checkpoints, managed data recovery, and deployment controls support restoration after failures. Availability and recovery time are not guaranteed.
Data Isolation Between Companies
Authenticated requests resolve an active company membership, and supported database queries and storage reads apply company or user scope. Permission checks provide an additional boundary for sensitive actions.
Responsible Disclosure
We take security reports seriously. If you discover a potential vulnerability in EquipmentFlow, practice responsible disclosure and notify us privately before public disclosure. Please:
- Describe the affected page, workflow, and observed behavior;
- Avoid privacy violations, service disruption, social engineering, or destructive testing;
- Do not access, modify, retain, or disclose data that is not yours; and
- Allow reasonable time for investigation and remediation before disclosure.
Please do not access, modify, or delete data belonging to other users as part of your research.
Report a Security Issue
Found a vulnerability? Please reach out to our security team directly. Do not report security issues through public channels.
Report securelySecurity Contact
To report a vulnerability, use the secure security report form. For account-level security concerns (compromised account, unauthorized access), contact support@equipmentflowco.com.
Have a security question that isn't covered here? Reach out to our team — we're happy to discuss our security practices with enterprise customers and prospects.