Back to Home

Security at Work Flow Trade

Last updated: July 2026

Your business runs on your data — customers, jobs, quotes, timesheets, staff records. Protecting it is not an afterthought for us; it is engineered into every layer of the platform. This page explains, in plain language, exactly how your data is protected.

Encryption

  • In transit: all connections to Work Flow Trade use TLS (HTTPS), enforced with HTTP Strict Transport Security so browsers refuse to connect insecurely.
  • At rest: data is stored on MongoDB Atlas with platform-level encryption at rest. On top of that, particularly sensitive fields — such as two-factor authentication secrets and third-party integration tokens — are additionally encrypted at the application level with AES-256-GCM.

Passwords & Sign-in

  • Passwords are hashed with bcrypt and are never stored, transmitted, or logged in plain text.
  • Sign-in is protected by layered rate limiting that blocks brute-force and credential-stuffing attempts — and the protection survives server restarts.
  • Sessions use short-lived access tokens with securely rotated refresh tokens. Refresh and reset tokens are stored only as one-way hashes.
  • Changing your password or email immediately signs out every other session on the account.
  • Changing your login email requires your current password and email confirmation, with a one-click undo sent to your old address — so a stolen session alone can never take over an account.
  • Two-factor authentication (authenticator app) is available on all accounts, with encrypted secrets and single-use backup codes.

Your Data Stays Yours

  • Strict company isolation: every database query is scoped to your company. Company identity is derived server-side from your account record — never from anything the client sends — so it cannot be spoofed or tampered with.
  • Role-based access: owners, admins, dispatchers, field staff and portal customers each see only what their role permits. Sensitive actions like user management and billing are owner-restricted.
  • Customer portal: portal users are additionally scoped to their own customer record, and only see documents explicitly shared with them.
  • We never sell or share your data with third parties for marketing purposes.

Payments

All payments are processed by Stripe, a PCI DSS Level 1 certified payment provider — the highest level of certification in the payments industry. Card numbers never touch our servers and we never store them.

Infrastructure & Hardening

  • Hosted on Render (application) and MongoDB Atlas (database) — managed, professionally operated cloud infrastructure with automated backups.
  • Modern browser security headers (Content Security Policy, HSTS, referrer policy) and a strict cross-origin allowlist.
  • Request sanitisation against injection attacks on every request, plus explicit field-level guards on all updates.
  • File uploads are validated by both declared type and actual file content (magic bytes), size-limited, and rate-limited.
  • Layered rate limiting across the platform: global, sign-in, uploads, and imports.
  • Audit logging of security-relevant actions — sign-in attempts, permission changes, deletions, and administrative activity.

Compliance & Certifications

  • NZ Privacy Act 2020: we operate under and comply with New Zealand's privacy law — see our Privacy Policy for your rights and how we handle personal information.
  • PCI DSS: payment card handling is covered by Stripe's Level 1 certification.
  • ISO 27001 / SOC 2: we do not yet hold these formal audit certifications — they are enterprise-scale programmes we plan to pursue as we grow. Not holding them is normal for a company of our size, and it does not change any of the protections described above.

What You Can Do

  • Use a strong, unique password for your account.
  • Enable two-factor authentication in your account settings.
  • Give staff the lowest role that lets them do their job, and deactivate accounts when people leave.

Reporting a Security Issue

If you believe you have found a security vulnerability in Work Flow Trade, we want to hear about it and will respond promptly. Email support@workflowtrade.co.nz with "Security" in the subject line. Please give us a reasonable opportunity to investigate and fix an issue before disclosing it publicly.