Security

Security, described plainly

FenceTracer is a multi-tenant application for contractor business data. This page describes product safeguards; it is not a certification, audit report, or guarantee of security.

Accounts and access

Passwords are stored as argon2 hashes rather than plaintext. Cookie-backed sessions are validated server-side, and workspace data is scoped to the user's company. Administrators control team invitations and roles.

Transport and browser protections

The public application uses HTTPS. The site also sends security headers including HSTS, content-type protection, frame restrictions, a referrer policy, and a restrictive permissions policy.

Operational data

FenceTracer uses service providers for application hosting, database and backend functions, transactional email, payments, analytics, and mobile distribution. The current provider list and data-retention details are in the Privacy Policy.

Payments

Subscription payments are processed by Stripe. FenceTracer does not store full payment-card numbers.

Report a concern

Please report a suspected vulnerability privately to [email protected], with enough detail to reproduce it. Do not include customer data or publicly disclose an issue before we can investigate.