CCContractorComply

SECURITY & DATA PROTECTION

Practical safeguards for contractor records.

ContractorComply is designed to keep company, project, document, payroll-support, and subscription records available to authorized users while limiting unnecessary exposure.

AUTHENTICATED WORKSPACESPRIVATE FILE STORAGECOMPANY-SCOPED ACCESS

SHARED RESPONSIBILITY

Security is built into the workflow—and maintained by both sides.

ContractorComply applies technical and operational safeguards to the service. Customers remain responsible for choosing authorized users, protecting devices and passwords, reviewing permissions, uploading only necessary information, and maintaining any legally required independent archives.

CURRENT SAFEGUARDS

How access and records are protected.

01

Authenticated access

Customer workspaces require an authenticated account. Company roles help control who can view records and who can make changes.

02

Company-scoped records

Database tables use company identifiers, permissions, and row-level security policies designed to keep one customer’s records separate from another customer’s workspace.

03

Private document storage

Uploaded compliance documents are stored in a private Supabase Storage bucket. Access policies and signed, time-limited links are used instead of public document URLs.

04

Protected service credentials

Publishable browser credentials are paired with database policies. Privileged service and billing credentials are restricted to server-side environments and are not intended for browser exposure.

05

Hosted payment collection

Stripe Checkout collects payment-card information on Stripe-hosted pages. ContractorComply stores subscription and customer references, not complete payment-card numbers.

06

Operational controls

Archive, deletion, export, account roles, document review, project assignment, and activity records give authorized teams practical control over the information they maintain.

WHERE INFORMATION IS HANDLED

A clear view of the service providers behind the platform.

InformationPrimary serviceHow it is handled
Account, company, project, and workflow recordsSupabase PostgreSQL databaseRestricted through authenticated access, grants, and row-level policies.
Uploaded documents and field photosPrivate Supabase StorageCompany-scoped storage paths and access policies; files are not intentionally published as open URLs.
Payment-card informationStripe-hosted Checkout and billing systemsComplete card details are handled by Stripe and are not intended to pass through ContractorComply servers.
Application delivery and server functionsNetlifyHosts the public application and approved server-side workflows.
Transactional account emailConfigured email-delivery providersUsed for confirmation, password recovery, billing, welcome, support, and other service messages.

Service providers maintain their own security programs and contractual terms. Their certifications do not automatically make ContractorComply—or a customer’s use of it—compliant with every specialized framework.

ACCESS

Roles, authentication, and company separation

Signed-in users receive access through their company account and assigned role. Database and storage policies are designed to evaluate the current company before allowing access to customer records. Customers should remove former team members promptly, use unique passwords, and limit administrative access.

TRANSMISSION

Connections and hosted infrastructure

The application is delivered over HTTPS. Supabase states that information within its platform is encrypted in transit and at rest, subject to its documentation and shared-responsibility model. ContractorComply does not promise that any internet-connected system is immune from every threat.

RETENTION

Archive, export, deletion, and backups

Authorized users can archive or delete supported records and export available project information. Deletion requests may be limited by account authority, legal or security needs, billing records, and provider backup cycles. Database backups do not necessarily include every stored file, so customers should retain independent copies required by contracts, laws, owners, or agencies.

PAYMENTS

Stripe handles complete card information

Subscription checkout and customer billing management use Stripe-hosted pages. ContractorComply receives the identifiers and status information needed to activate plans and display subscription access, while complete card details remain within Stripe’s payment environment.

LIMITS

No specialized certification is implied

ContractorComply is not currently represented as HIPAA, FedRAMP, CMMC, or government-authorized software. It does not certify a contractor’s legal, payroll, safety, cybersecurity, or regulatory compliance. Customers must determine whether the service is appropriate for their contracts and information.

INCIDENTS

Report a security concern

If you believe an account, file, or ContractorComply workflow may have been accessed improperly, contact support@contractorcomply.us. Include your company name, affected account, approximate time, and a safe description—but do not email passwords, API keys, Social Security numbers, or complete payment-card information.

QUESTIONS ABOUT YOUR DATA?

Ask before uploading sensitive information.

We can explain the current platform design, account controls, and service-provider roles so your company can make an informed decision.

Contact support