Security
This page lists controls that are in the product today. It does not claim SOC 2, ISO, HIPAA, or a third-party audit we have not bought.
Who can see a shop's data
Each login sees its own rows. Database policies use the signed-in user id. A teammate sees the owner's workspace only after the owner invites them. The service-role key used by servers and agents bypasses those policies and is never shipped to the browser.
Payments
Cards go to Stripe. We do not store card numbers. PoolWright is $99/month. Each Wright app has its own Stripe webhook secret so a Restore event cannot mark a Roof shop paid.
Photos
Job photos go in a private bucket. Links are signed. We do not put customer job photos on a public CDN path.
Outbound customer mail goes through a send gate (unsubscribe, frequency, halt switch). Contact form rows are stored before the confirmation email is sent.
What this is not
Not a pentest report. Not an insurance policy. Not "bank-grade" marketing. If a control is not on this page, do not assume it exists.
Privacy · Terms · Start free