Your business runs on your data — customers, jobs, quotes, timesheets, staff records. Protecting it is not an afterthought for us; it is engineered into every layer of the platform. This page explains, in plain language, exactly how your data is protected.
Encryption
In transit: all connections to Work Flow Trade use TLS (HTTPS), enforced with HTTP Strict Transport Security so browsers refuse to connect insecurely.
At rest: data is stored on MongoDB Atlas with platform-level encryption at rest. On top of that, particularly sensitive fields — such as two-factor authentication secrets and third-party integration tokens — are additionally encrypted at the application level with AES-256-GCM.
Passwords & Sign-in
Passwords are hashed with bcrypt and are never stored, transmitted, or logged in plain text.
Sign-in is protected by layered rate limiting that blocks brute-force and credential-stuffing attempts — and the protection survives server restarts.
Sessions use short-lived access tokens with securely rotated refresh tokens. Refresh and reset tokens are stored only as one-way hashes.
Changing your password or email immediately signs out every other session on the account.
Changing your login email requires your current password and email confirmation, with a one-click undo sent to your old address — so a stolen session alone can never take over an account.
Two-factor authentication (authenticator app) is available on all accounts, with encrypted secrets and single-use backup codes.
Your Data Stays Yours
Strict company isolation: every database query is scoped to your company. Company identity is derived server-side from your account record — never from anything the client sends — so it cannot be spoofed or tampered with.
Role-based access: owners, admins, dispatchers, field staff and portal customers each see only what their role permits. Sensitive actions like user management and billing are owner-restricted.
Customer portal: portal users are additionally scoped to their own customer record, and only see documents explicitly shared with them.
We never sell or share your data with third parties for marketing purposes.
Payments
All payments are processed by Stripe, a PCI DSS Level 1 certified payment provider — the highest level of certification in the payments industry. Card numbers never touch our servers and we never store them.
Infrastructure & Hardening
Hosted on Render (application) and MongoDB Atlas (database) — managed, professionally operated cloud infrastructure with automated backups.
Modern browser security headers (Content Security Policy, HSTS, referrer policy) and a strict cross-origin allowlist.
Request sanitisation against injection attacks on every request, plus explicit field-level guards on all updates.
File uploads are validated by both declared type and actual file content (magic bytes), size-limited, and rate-limited.
Layered rate limiting across the platform: global, sign-in, uploads, and imports.
Audit logging of security-relevant actions — sign-in attempts, permission changes, deletions, and administrative activity.
Compliance & Certifications
NZ Privacy Act 2020: we operate under and comply with New Zealand's privacy law — see our Privacy Policy for your rights and how we handle personal information.
PCI DSS: payment card handling is covered by Stripe's Level 1 certification.
ISO 27001 / SOC 2: we do not yet hold these formal audit certifications — they are enterprise-scale programmes we plan to pursue as we grow. Not holding them is normal for a company of our size, and it does not change any of the protections described above.
What You Can Do
Use a strong, unique password for your account.
Enable two-factor authentication in your account settings.
Give staff the lowest role that lets them do their job, and deactivate accounts when people leave.
Reporting a Security Issue
If you believe you have found a security vulnerability in Work Flow Trade, we want to hear about it and will respond promptly. Email support@workflowtrade.co.nz with "Security" in the subject line. Please give us a reasonable opportunity to investigate and fix an issue before disclosing it publicly.