Security

How SiteStride protects builder and client data

Your jobs hold margins, contracts, homeowner details and safety records. Here's plainly how that data is stored, who can reach it, how it's backed up, and how you get it back out.

The essentials

Data protection

All traffic between your browser and SiteStride runs over HTTPS/TLS. Job data is stored in a managed cloud database with encryption at rest provided by the hosting platform, and uploaded files (photos, plans, invoices) live in access-controlled storage rather than public links.

Access controls

Every record is scoped to your company. Roles decide what a person sees: office roles get costs, margins and client billing; site roles get Onsite — tasks, diary, timesheets, safety — with pay rates and job financials withheld. Permissions are enforced on the server, not just hidden in the interface.

Client and trade access

Client portals, quote links, RFQs and site check-ins are opened per job with a signed link, and every request is validated server-side before any data is returned. You switch a job's portal on or off at any time, and shared views never expose internal costs, rates or task detail.

Backups & availability

The database runs on managed cloud infrastructure with automated backups and point-in-time recovery handled by the platform. Uploaded files are stored redundantly. You can also export your own copies of schedules, costs and records whenever you like.

Accounts & sign-in

Sign-in is email/password or Google, with sessions issued as short-lived tokens. Passwords are never stored by SiteStride in readable form. Company admins can invite, re-role and remove users, and removing a user revokes their access immediately.

Your data stays yours

Schedules, estimates, cost actuals, timesheets and site records export to PDF or CSV on demand. If you close your account, request a full export and deletion — we don't hold your job history hostage.

How we handle your data

Different data on a job deserves different treatment. This is the rule we apply to each kind.

Builder data

Estimates, budgets, purchase orders, invoices, timesheets and pay-related fields are treated as commercially sensitive. Pay rates and targets are readable only by managers and admins in your company, through server-side checks — never fetched into a site user's browser.

Client data

Homeowner names, addresses, contact details and selections are used to run their job and nothing else. We don't sell data, and we don't use client contact details for our own marketing.

Site and safety records

Inductions, SWMS sign-offs, credentials and incident reports are kept against the job they belong to with an audit trail, so the record you produce later matches the record that was signed at the time.

Photos and attachments

Site photos, plans and receipts are stored against the job with the same role rules as the job itself. Files are served through authorised, expiring links rather than open public URLs.

Engineering practices

  • Company-level data isolation enforced at the database layer on every table.
  • Automated security scanning of the database policies and dependencies as part of each release.
  • Least-privilege service credentials; privileged operations run server-side only.
  • Secrets and API keys stored in managed secret storage, never in the app bundle.
  • Audit trails on variations, signatures, approvals and safety records.

Reporting a security issue

If you believe you've found a vulnerability in SiteStride, please report it before sharing it publicly. Include the URL, what you did and what you saw, and we'll confirm receipt and keep you updated while we investigate.

Or email us directly: support@sitestride.net

Protected by bot detection and rate limiting. Please don't include live customer data.

This page describes how SiteStride is built and operated today. It is not a certification or audit statement, and it may change as the product does.

Run your jobs somewhere sensible

Unlimited site and trade users on every plan — see what each tier includes.

View pricing