Security

Your business runs on the data in Maintaire — customer records, agreements, invoices, equipment histories. Here’s how we protect it.

Application security

  • Tenant isolation: every record is scoped to your organization at the database layer; all queries are organization-filtered so one customer can never read another’s data.
  • Encryption in transit: all traffic is served over TLS, with HSTS and hardened security headers (CSP, frame-ancestors, nosniff).
  • Passwords: stored only as salted bcrypt hashes. Email verification is required for new accounts; password resets use single-use, expiring tokens.
  • Role-based access: owner, admin, dispatcher, technician, and accounting roles in the app, plus separate restricted roles for customer-portal users.
  • Rate limiting: authentication and other sensitive endpoints are rate-limited to slow credential-stuffing and abuse.
  • Shared links: public invoice, report, and signing links use long, unguessable random tokens and can be revoked.
  • Auditability: administrative actions and electronic signatures are logged with actor, timestamp, and IP address.

Payments

All payments are processed by Stripe on Stripe-hosted pages. Card numbers never touch our servers — we store only payment tokens, card brand, and last four digits. This keeps Maintaire in the lightest PCI DSS scope (SAQ A).

Infrastructure

The Service is hosted with Render in [FILL IN: Canada / the United States], with encrypted storage and automated backups. Third parties that process data on our behalf are listed at /legal/subprocessors.

Incident response

We maintain a breach-response process aligned with PIPEDA and Quebec Law 25: assess the risk of significant harm, notify affected customers and regulators where required, and keep records of all incidents for at least 24 months.

Reporting a vulnerability

If you believe you’ve found a security issue, email security@maintaire.com (also published at /.well-known/security.txt). Please include steps to reproduce and give us reasonable time to fix the issue before public disclosure. We won’t pursue legal action against good-faith research that respects user data and service availability.