Legal
Security
Effective: August 20, 2026
Protecting your workforce data, operational records, and client information is foundational to everything we build. This page describes how Attlock approaches security across infrastructure, application, and organizational layers.
To report a security concern or vulnerability, contact us at support@attlock.com. We acknowledge all reports within 3 business days.
Compliance and Assessments
SOC 2 Readiness
Platform built following SOC 2 trust service criteria. Formal certification on our roadmap.
GDPR
Data Processing Agreements and Standard Contractual Clauses available on request.
Canadian privacy readiness
Attlock is implementing controls intended to support customer obligations under applicable Canadian privacy laws. Compliance depends on configuration, contracts, customer practices, and jurisdiction.
Security Reviews
Regular internal security reviews and vulnerability assessments across all services.
For enterprise customers who require compliance documentation, security questionnaire responses, or a Data Processing Agreement, please contact support@attlock.com.
Infrastructure Security
Core Attlock application data is currently hosted with Convex in US East (Northern Virginia). Other service providers may process limited information in Canada, the United States, or other disclosed locations. The standard hosted service does not currently provide Canada-only data residency.
Québec and cross-border processing
Québec customers receive an explicit US-hosting and cross-border processing disclosure during onboarding. Attlock maintains internal privacy-impact assessment records for material cross-border processing and provider changes.
Attlock's infrastructure controls include:
- Cloud Hosting: Core application data is hosted with Convex in US East (Northern Virginia).
- Network Security: All services operate within private networks with strict firewall rules, network segmentation, and intrusion detection systems. No public exposure of internal services.
- Availability: We monitor the platform for availability and investigate service alerts. Monitor real-time status at status.attlock.com.
- Secrets Management: All credentials, API keys, and tokens are stored in dedicated secrets management systems with audit logging. No secrets in source code.
- CI/CD Security: Automated builds with dependency vulnerability scanning, static analysis, and signed deployments.
Encryption
In Transit
All data transmitted between clients and servers is encrypted via TLS 1.2+ (HTTPS). Internal service-to-service communication is encrypted. We enforce HSTS and support modern cipher suites only.
At Rest
All stored data, including database records, file uploads, backups, and logs, is encrypted at rest using AES-256 or equivalent industry-standard algorithms.
Authentication and Access Control
- Authentication: User authentication is managed by an enterprise identity platform supporting email/password, SSO, social login, and multi-factor authentication (MFA).
- Role-Based Access Control (RBAC): Every user is assigned a role (Owner, Admin, Supervisor, Guard, Client) with granular permissions. Access to data and actions is enforced both in the UI and at the API layer.
- Multi-Tenant Isolation: All data is scoped by company. Every query, mutation, and action validates the user's identity and company association before any data is accessed or modified. Cross-tenant data access is architecturally prevented.
- Session Management: Sessions are time-limited with automatic expiration. Refresh tokens are rotated and revoked upon sign-out.
- Internal Access: Attlock employee access to production systems follows least-privilege principles. All access requires MFA and is audit-logged.
Application Security
- Input Validation: All external inputs are validated and sanitized at API boundaries before processing.
- OWASP Protection: The platform is built with protections against common web vulnerabilities including XSS, CSRF, SQL injection, and broken authentication patterns.
- API Security: All API endpoints require authentication. Rate limiting, request throttling, and abuse detection are enforced to prevent misuse.
- Dependency Scanning: Third-party dependencies are continuously monitored for known vulnerabilities with automated alerts and remediation workflows.
- Code Review: All code changes undergo review before deployment. Security-sensitive changes require additional sign-off.
Mobile Application Security
Attlock's mobile applications are built with security-first principles:
- Permission-Based Access: Location, camera, microphone, and storage permissions must be explicitly granted by the user. All permissions can be revoked at any time via device settings.
- Data on Device: No sensitive data is stored permanently on device. Captured media (photos, videos) is uploaded to encrypted storage and removed from local storage after upload.
- Sign-Out Enforcement: All background services (GPS tracking, push notifications) cease immediately upon sign-out. No data transmission occurs when the user is signed out.
- Secure Communication: All mobile API calls use HTTPS with certificate pinning where supported.
Third-Party Services
We use a limited number of vetted third-party service providers to deliver the platform. All providers are evaluated for security posture, bound by data processing agreements, and subject to periodic review.
Our providers fall into these categories:
- Cloud Infrastructure & Hosting: Convex hosts core application data. We also use specialized providers for storage, delivery, and monitoring; processing details are available on request.
- Authentication & Identity: Dedicated identity platform supporting SSO, MFA, and session management.
- Payment Processing: PCI DSS Level 1 certified payment processor. Attlock does not store credit card numbers.
- Communications: Transactional email delivery with minimal data exposure (email addresses only).
- Monitoring & Analytics: Error tracking and performance monitoring services that do not process customer business data.
Enterprise customers may request our full subprocessor list with processing details and data residency information by contacting support@attlock.com.
Organizational Security
- Security Training: All team members complete security awareness training covering data handling, phishing prevention, and incident reporting.
- Confidentiality: All employees and contractors sign confidentiality and non-disclosure agreements before accessing any systems or data.
- Least Privilege: Production access is restricted to personnel with a documented need. Access is reviewed periodically and revoked upon role change or departure.
- Vendor Management: Third-party providers are evaluated for security posture before onboarding and reviewed periodically. Providers processing customer data must sign DPAs.
Incident Response
Attlock maintains security-response procedures and is expanding its formal privacy-incident register, notification evidence, exercises, and governance. Customers are notified according to applicable law and contractual terms when a confirmed incident affects their information.
- Detection: Continuous monitoring with automated alerting for anomalous activity, unauthorized access attempts, and system failures.
- Response: Predefined runbooks for common incident types with clear ownership and escalation timelines.
- Notification: Confirmed incidents are handled according to applicable legal and contractual notification requirements.
- Post-Incident: Root cause analysis conducted for all incidents with documented corrective actions to prevent recurrence.
Data Retention and Deletion
Attlock retains customer data according to the applicable agreement, customer-configured retention settings, legal requirements, active legal holds, and the lifecycle of the service providers involved. Account closure first restricts access and may use soft deletion or archival while verified deletion steps are completed. Provider backups expire according to provider recovery policies and are not represented as immediately erased.
Account Deletion
Account owners can request full account deletion by contacting support@attlock.com. Account closure restricts access while applicable retention and verified deletion steps are completed.
Timing depends on data category, legal obligations, active legal holds, and provider backup lifecycles. Billing and other records may be retained where required by tax, financial, or other applicable law.
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a vulnerability in any Attlock service:
- Email support@attlock.com with details of the vulnerability, including steps to reproduce.
- We will acknowledge your report within 3 business days.
- We will provide an initial assessment and expected timeline for remediation within 10 business days.
- We will notify you when the vulnerability has been resolved.
- Critical vulnerabilities affecting customer data will be communicated to affected customers via email.
We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it. We do not pursue legal action against researchers who follow responsible disclosure practices.
Questions
For security-related questions, compliance documentation requests, or to report a concern:
This page should be read alongside our Privacy Policy and Terms of Service.