Security & Trust Center

Enterprise-grade security built for franchise networks handling sensitive customer and operational data.

Last updated: June 2026

Security at a Glance

Encryption at Rest

AES-256 encryption on all stored data via Supabase infrastructure. Sensitive fields (API keys, OAuth tokens, contractor tax IDs, payment data) are stored in isolated restricted tables with no client-side access.

Encryption in Transit

TLS 1.3 enforced on all connections. WebSocket streams use HMAC-SHA256 signed tokens with 60-second expiry for voice session authentication.

Tenant Isolation

Row-Level Security (RLS) enforced at the database level. Every query is scoped to the authenticated tenant. Cross-tenant data access is structurally impossible at the database layer.

Data Residency

All data is stored in United States data centers. No data is transferred outside the US without explicit consent.

Access Control

Role-based access control with 12 defined roles (owner, admin, dispatcher, technician, franchisor, franchise_admin, platform_admin, and more). Every UI route and API endpoint enforces role-appropriate access.

Compliance Roadmap

SOC 2 Type II audit in progress — estimated completion Q1 2027. GDPR and CCPA data deletion capabilities available on request.

How We Handle Your Data

What data we collect
  • Business operational data (jobs, customers, invoices, technicians)
  • AI voice call recordings and transcripts (with customer consent)
  • Lead source and marketing performance data
  • Payment method details (stored via Stripe — we never store raw card numbers)
  • Usage data for AI billing and platform analytics
How data is isolated per tenant
Every business account is completely isolated from all other accounts. Our Row-Level Security architecture ensures that even if two businesses use the same database infrastructure, their data is inaccessible to each other at the query level. Platform administrators cannot access tenant data without explicit audit logging.
Data retention
  • Call transcripts: retained for 90 days by default, configurable per account
  • Lead and job data: retained for the life of the account
  • Activity logs: retained for 12 months
  • On account deletion: all data purged within 30 days
Your rights (GDPR/CCPA)
You may request export of all your data at any time. You may request deletion of your account and all associated data. We will process all requests within 30 days. Contact: info@jobospro.com

AI Agents — What They Can and Cannot Do

JobOS Pro uses 10 purpose-built AI agents. Here is exactly what write access each one has.

Kate
AI Voice Receptionist
What it does

Answers inbound calls, books jobs, logs activity.

Write access

Creates customer records, job records, activity logs — only when a caller provides consent. Bounded by the dialed business number; cannot access other tenants.

Iris
Lead Capture
What it does

Captures leads from web forms and LSA webhooks.

Write access

Creates lead records. Source-verified via signed webhook secrets.

Max
Dispatch Intelligence
What it does

Recommends and applies technician assignments.

Write access

Updates job assignment fields only. Cannot create or delete records.

Cal
Schedule Optimization
What it does

Surfaces schedule gap analysis.

Write access

Read-only. No write access.

Ava
Follow-Up Agent
What it does

Sends post-job follow-up SMS via Twilio.

Write access

Send-only. Cannot modify job or customer records.

Stella
Review Automation
What it does

Requests reviews via SMS/email.

Write access

Sends review request SMS/email and creates review request records. Cannot post to external platforms without owner approval.

Finn
AI Financial Operations Manager
What it does

Follows up on unpaid invoices and computes job profitability from existing records.

Write access

Sends follow-up SMS. Cannot modify invoice amounts or status.

Rex
AI Chief Growth Officer
What it does

Identifies upsell, membership & referral opportunities from existing job history.

Write access

Read-only.

Grace
Customer Retention
What it does

Sends re-engagement SMS.

Write access

Send-only. Cannot modify customer records.

Scout
Network Intelligence
What it does

Surfaces cross-network benchmarks.

Write access

Read-only at franchisee level. Corporate view requires explicit org membership.

Infrastructure & Reliability

Hosting
Vercel (frontend) + Railway (backend)
Database
Supabase (PostgreSQL) — US region
Payments
Stripe (PCI DSS compliant)
Voice
Twilio + OpenAI GPT-4o Realtime

Uptime commitment

We target 99.9% uptime for all core services. Railway provides automatic restart on failure with max 5 retry attempts. Health monitoring runs continuously on the /health endpoint.

Incident response

Security incidents are reported to affected tenants within 24 hours of discovery. Contact: info@jobospro.com

Automated Communications Compliance

JobOS Pro sends automated SMS and email communications on behalf of your business. All automated communications comply with TCPA requirements:

  • Customers receive disclosure before any AI voice call is recorded
  • All SMS sequences include opt-out instructions
  • STOP responses are processed immediately and permanently remove the contact from all automated sequences
  • Review request SMS includes business identification and opt-out language
  • You control all message templates and can disable any automation at any time

Agreements & Documentation

Privacy Policy

Our full privacy policy covering data collection, use, and your rights.

View Privacy Policy

Terms of Service

Complete terms governing use of the JobOS Pro platform.

View Terms of Service

Data Processing Agreement

DPA available for enterprise customers requiring formal data processing agreements.

Request DPA

Security Contact

Found a vulnerability? We take security reports seriously and will respond within 24 hours.

info@jobospro.com

For data privacy requests (export, deletion, GDPR/CCPA):

info@jobospro.com

For enterprise procurement and compliance documentation:

info@jobospro.com

JobOS Pro is built for enterprise franchise networks. We understand the responsibility of handling operational data across thousands of locations. Security is not a feature — it is the foundation.