Loading EquipmentFlow…

Trust & Compliance

Last Updated: August 27, 2026

Learn how EquipmentFlow protects company data, secures user access, and supports responsible platform operations.

Version2.1
EffectiveAugust 27, 2026
What's ChangedAligned the trust center with current free access, legal versions, service providers, retention practices, and verified safeguards.
EquipmentFlow is a workflow and recordkeeping service, not legal, safety, payroll, tax, inspection, or regulatory advice. Customers should have their own policies and obligations reviewed by qualified professionals.

Security

EquipmentFlow is built with security controls at every layer of the application. The following controls are implemented and active in the production system.

Secure Authentication via Clerk

User sign-in and session management are handled by Clerk through supported email and Google sign-in flows. EquipmentFlow does not store Clerk account passwords.

Role-Based Permissions

Protected workflows combine company membership, roles, and granular server-side permissions. Authorized company leaders can configure access for their team.

Company-Level Data Isolation

Authenticated requests resolve an active company membership, and supported database and storage operations apply company or user scope.

Audit Logging

Supported significant actions produce timestamped audit or activity records with actor and change context for authorized review.

Server-Side Authorization

Protected API workflows enforce authorization on the server. Client-side visibility controls supplement, rather than replace, those checks.

Secure Invitation Tokens

Email invitation links and QR join tokens use unpredictable values and server-side validation. Invitations may expire, be revoked, or become invalid after use.

Protected File Storage

Uploaded files (equipment photos, JSA attachments, repair images) are stored in access-controlled object storage. Files are not publicly accessible without a valid authenticated session.

Encryption in Transit

Production web traffic is served over HTTPS through managed hosting.

Note: EquipmentFlow does not currently hold SOC 2, ISO 27001, or HIPAA certifications. Formal third-party penetration testing has not been completed. See the Compliance Roadmap below.

For full security documentation, visit the Security page.

Privacy & Legal

EquipmentFlow's legal documents govern data handling, service terms, and acceptable use. Each document is reviewed and updated as the platform evolves.

Data Protection

Data Processing Addendum

EquipmentFlow offers a Data Processing Addendum (DPA) for organizations with specific compliance requirements. The DPA covers processor obligations, subprocessor disclosure, data-subject rights, breach notification, and international transfer mechanisms.

For organizations requiring a signed DPA: contact support@equipmentflowco.com. The DPA is not automatically executed — it requires a request and counter-signature.

Data Processing Addendum

Full DPA text covering definitions, roles, subprocessors, security measures, international transfers, and breach notification.

Customer Data Ownership

All data you enter into EquipmentFlow — equipment records, repair histories, JSA documents, uploaded photos — belongs to your company. EquipmentFlow processes it solely to deliver the service. We do not sell, license, or transfer your operational data to third parties.

Data Retention

Company data is retained while the account is active and as needed for service, legal, audit, security, and dispute purposes. Deletion follows the account-deletion process and applicable recovery or retention windows described in the Privacy Policy.

Account & Company Deletion

Company owners can initiate company deletion from Settings. Deletion removes company access and schedules eligible company records and files for deletion, subject to legal, audit, security, and managed-recovery retention. Contact support@equipmentflowco.com before deletion if records must be exported.

Key Service Providers

The following third-party providers are currently integrated and operational in the EquipmentFlow production system:

ProviderPurposeLocation
Clerk User authentication and identityUnited States
Resend Transactional email deliveryUnited States
Replit Application hosting and infrastructureUnited States

This list reflects providers verified as active in the production system. EquipmentFlow will update this list when providers are added or changed.

Compliance Roadmap

EquipmentFlow is a growing platform. The following reflects the current state of formal security and compliance programs honestly and accurately.

SOC 2 Type II certificationNot currently certified
ISO 27001 certificationNot currently certified
Formal penetration testingPlanned
HIPAA compliance assessmentNot applicable
Public bug bounty programPlanned
Additional compliance documentationPlanned
EquipmentFlow will update this page as formal security and compliance programs are established.

Service Reliability

System Status

Public system-status reporting is planned. A dedicated status page will be linked here when available.

EquipmentFlow does not publish uptime guarantees or service-level agreements at this time. The platform is operated with attention to availability, and incidents are addressed as promptly as resources allow.

Incident Communication

When significant service disruptions occur, EquipmentFlow will communicate with affected account owners via email. For time-sensitive issues, contact support@equipmentflowco.com directly.

Support Contact

For platform issues, company-access questions, or account-level concerns, contact support@equipmentflowco.com. You can also submit a request through the Support Center.

Report a Security Concern

If you discover a potential security vulnerability in EquipmentFlow, we ask that you report it privately. Responsible disclosure helps us protect all users.

Guidelines

  • Provide a clear description of the issue
  • Include steps to reproduce when possible
  • Do not access, modify, or delete data that does not belong to you
  • Do not publicly disclose the issue until it has been resolved
  • Allow reasonable time for investigation before escalating

We review reports as resources allow and may contact the reporter for reproduction details, impact information, or coordinated-disclosure planning.

Report a Security Issue

Send a detailed report to our security team. Do not use public channels for unresolved vulnerabilities.

Report a Security Issue

Contact Information

Privacy inquiries are currently handled by the support team at support@equipmentflowco.com.