Security
Your business runs on the data in Maintaire — customer records, agreements, invoices, equipment histories. Here’s how we protect it.
Application security
- Tenant isolation: every record is scoped to your organization at the database layer; all queries are organization-filtered so one customer can never read another’s data.
- Encryption in transit: all traffic is served over TLS, with HSTS and hardened security headers (CSP, frame-ancestors, nosniff).
- Passwords: stored only as salted bcrypt hashes. Email verification is required for new accounts; password resets use single-use, expiring tokens.
- Role-based access: owner, admin, dispatcher, technician, and accounting roles in the app, plus separate restricted roles for customer-portal users.
- Rate limiting: authentication and other sensitive endpoints are rate-limited to slow credential-stuffing and abuse.
- Shared links: public invoice, report, and signing links use long, unguessable random tokens and can be revoked.
- Auditability: administrative actions and electronic signatures are logged with actor, timestamp, and IP address.
Payments
All payments are processed by Stripe on Stripe-hosted pages. Card numbers never touch our servers — we store only payment tokens, card brand, and last four digits. This keeps Maintaire in the lightest PCI DSS scope (SAQ A).
Infrastructure
The Service is hosted with Render in [FILL IN: Canada / the United States], with encrypted storage and automated backups. Third parties that process data on our behalf are listed at /legal/subprocessors.
Incident response
We maintain a breach-response process aligned with PIPEDA and Quebec Law 25: assess the risk of significant harm, notify affected customers and regulators where required, and keep records of all incidents for at least 24 months.
Reporting a vulnerability
If you believe you’ve found a security issue, email security@maintaire.com (also published at /.well-known/security.txt). Please include steps to reproduce and give us reasonable time to fix the issue before public disclosure. We won’t pursue legal action against good-faith research that respects user data and service availability.