Security
Your customer list is the business. We treat it that way.
You're about to put every customer, quote and dollar of history into software you didn't write. Here is exactly how it's protected, and exactly how you get it back out.
01
Your data is walled off at the database
Every record carries the business it belongs to, and the database itself refuses to return another company's rows — it isn't a filter in our code that could be forgotten. Access is enforced in three independent places: the page you load, the API you call, and the database row itself.
02
Staff only see what their job needs
Five roles, from owner down to field technician. A technician sees their assigned jobs, checklists and photos — not your customer list, not your pricing, not your margins, not your books. Enforced at the database, not just hidden in the menu.
03
We never hold your customers' card numbers
Card payments run through Stripe, a PCI Level 1 provider. Card details go from your customer's browser to Stripe directly and never touch our servers. Payouts land in your own bank account, with the exact processing fee itemised on every transfer.
04
You can leave with everything
One button exports your whole account as spreadsheets — customers, properties, jobs, quotes, invoices, payments, expenses and message history. It works even if your subscription has lapsed, because holding your customer list hostage isn't a business model. Secret customer links are stripped from the file so it's safe to email.
05
Messaging consent is enforced for you
Every text goes through a single opt-out checkpoint that fails closed — if we can't confirm someone is still subscribed, the message doesn't send. STOP, ARRÊT and their variants unsubscribe immediately across both texts and calls. Outbound campaigns default to your existing customers, not strangers.
06
We watch it so you don't find out from a customer
Every connected service is health-checked on a schedule, and server errors are tracked and alert us directly. Incoming webhooks from Stripe and Twilio are cryptographically verified, so nobody can forge a payment or a message into your account.
What we don't claim
We're not going to show you badges we haven't earned.
Vendira is not SOC 2 certified and has not had a third-party penetration test. We've done rigorous internal security review, and the protections above are real and verifiable — but certification is a specific thing with a specific auditor, and we'll tell you the day we have it and not before.
If your business requires a signed security questionnaire today, talk to us first so nobody wastes their time.
Get in touch