Security & Data Integrity
Trust, Engineered In
Field documentation is legal evidence. Here is how DTCD protects it — stated plainly, without security theater.
Record Integrity
Tamper-evident audit log
Closure and certification records are protected by an append-only, SHA-256 hash-chained audit log — each entry cryptographically linked to the one before it, so after-the-fact alteration is detectable.
Contemporaneous capture
GPS coordinates and timestamps are captured at the moment of documentation, in the field, not reconstructed later.
Access Control
Row-level security
Database-enforced isolation: every query is scoped to the requesting user's organization at the database layer, not just the application layer.
Modern authentication
Sign in with Apple, Google Sign-In, and email/password with server-side session management. Transport encrypted with TLS.
Infrastructure
Our underlying infrastructure providers — AWS, Cloudflare, and Supabase — maintain their own SOC 2 Type II attestations. Data is hosted in U.S. regions.
Data Practices
Your field records are your records: we do not sell personal data. Public data feeds carry work-zone information — not personal information. Worker-presence signals are opt-in and limited to active work-zone proximity. Full details in our Privacy Policy.
Responsible Disclosure
Found a security issue? Email matthew@purposebuilt.systems — reports go straight to the founder and are acted on quickly. PurposeBuilt Systems also maintains a registered DMCA agent; see Intellectual Property.