Security
Security, described plainly
FenceTracer is a multi-tenant application for contractor business data. This page describes product safeguards; it is not a certification, audit report, or guarantee of security.
Accounts and access
Passwords are stored as argon2 hashes rather than plaintext. Cookie-backed sessions are validated server-side, and workspace data is scoped to the user's company. Administrators control team invitations and roles.
Transport and browser protections
The public application uses HTTPS. The site also sends security headers including HSTS, content-type protection, frame restrictions, a referrer policy, and a restrictive permissions policy.
Operational data
FenceTracer uses service providers for application hosting, database and backend functions, transactional email, payments, analytics, and mobile distribution. The current provider list and data-retention details are in the Privacy Policy.
Payments
Subscription payments are processed by Stripe. FenceTracer does not store full payment-card numbers.
Report a concern
Please report a suspected vulnerability privately to [email protected], with enough detail to reproduce it. Do not include customer data or publicly disclose an issue before we can investigate.