Security
How we look after your data
Your customer list, your schedule and your money flow through Digital Arborist. Here is plainly what we do to protect them, and what we haven’t done yet.
Hosting
- Google Cloud, in the us-south1 region (Dallas, Texas)
- The app is reachable only through our load balancer, with Google Cloud Armor and rate limits in front
- Each firm’s data is kept separate in a shared database: every request is limited to the signed-in firm, and automated tests check it
Encryption
- HTTPS everywhere, TLS 1.2 or newer, with HSTS
- Database, backups and files encrypted at rest by Google Cloud
- Connection tokens and integration secrets encrypted again inside the app, under a key held in Google Secret Manager
- Passwords stored with bcrypt
Payments
- Card details are typed into Stripe’s own secure fields, on the web and in the iPhone app
- Card numbers never reach our servers, and our database has nowhere to store one
- Our PCI DSS assessment is in progress; we are preparing it as a service provider
Access
- Staff passwords must be at least 12 characters; repeated failed sign-ins lock the account for a while
- Role-based permissions on every action in the app
- Our own admin console requires an authenticator-app code
- Two-step sign-in for your owner and admin accounts is coming, not yet available
Backups and recovery
- Daily database backups, point-in-time recovery for the last 7 days, and monthly copies kept about 13 months
- Restores are tested every quarter; the last test restored the database in about 8.5 minutes
Monitoring and incidents
- Security events (sign-ins, permission changes, payments) are logged; platform logs are kept 400 days
- Alerts for errors and outages go straight to the owner
- If your firm’s data is exposed, we tell you within 72 hours of confirming it
Building the software
- Every release passes thousands of automated tests, including checks that keep firms’ data apart
- Automatic dependency alerts, and a scan for leaked secrets on every change
- Every release can be rolled back with one command
Your data, your call
- If you leave, your firm’s data, files and photos are deleted 90 days after cancellation, or sooner if you ask
- You can have an individual customer deleted; records you must keep for taxes stay unless you ask us to anonymise them
- We don’t train AI models on your data
- Your staff can connect their own AI assistant to the CRM only after an owner turns it on for your firm; data then flows to that provider under its terms, every action is audited, and you can disconnect any assistant at any time (setup docs)
What we haven’t done yet
- No SOC 2 report yet. We run a readiness program and will start the audit when customers need it
- No independent penetration test yet; it’s part of that audit
- We are a small company: the owner is the only person with access to customer data
Subprocessors
The companies that process data on our behalf, and what each one receives.
| Company | What for | Data it receives |
|---|---|---|
| Google Cloud | Hosting: application, database, file storage, networking, logging (region us-south1, Dallas, Texas) | All platform data |
| Stripe | Card and ACH payments, saved cards, platform billing | Customer name and email, payment amounts; card details are entered directly into Stripe and never reach us |
| Intuit QuickBooks | Accounting sync and invoice payments, for firms that connect it | Customer names, addresses and emails; invoices and payments |
| Google Workspace / Gmail API | Sending system email | Recipient addresses and message content |
| Google Maps Platform | Maps, geocoding and routing | Addresses |
| Google Business Profile APIs | Review and photo management, for firms that connect it | The firm’s Business Profile content |
| Anthropic | AI features: help chat, review and post drafting, reading the amount from check photos | Help-chat messages (personal details redacted first), draft text, check photos |
| PostcardMania | Direct-mail printing, for firms that use it | Recipient names and mailing addresses |
| hCaptcha | Bot protection on public forms | Visitor IP address and browser signals |
| GitHub | Source code and automated checks | Source code only; no customer data |
| Apple, Google Firebase | Mobile app distribution | App builds and tester emails |
Report a vulnerability
Found a security problem? Our disclosure details are in security.txt. Email hello@digitalarborist.com; we aim to reply within 5 business days. Please don’t access other people’s data or disrupt the service while testing.
Security documentation
Filling in a vendor security questionnaire, or need our policies? Email hello@digitalarborist.com and we’ll send what you need.