Security and reliability
Your data, in your own database.
SDRBO uses single-tenant isolation. Each customer workspace runs against its own database instead of sharing tables with every other account. Combined with role-based permissions and audit logging on every plan, that turns access questions into something you can answer with facts rather than assurances.
- Request over TLSEncrypted in transit, always
- Authenticated sessionCredentials hashed, never stored readable
- Role and permission checkRecord, field and action level
- Your workspace databaseNot a shared table filtered by account
- Write recorded in the audit logWho changed what, and when
- Backed up on schedulePoint-in-time recovery
How the platform is protected
Every item here is included at every price. Security is not a tier, because charging for it would mean selling the safe version of the product separately from the cheap one.
Isolated data per customer
Each workspace has a dedicated database. There is no shared table where a missing filter in one query could expose another company’s records.
Roles and permissions everywhere
Restrict records, fields and actions by role. Sensitive areas such as pay rates and workforce records can be limited to named administrators on any plan.
Audit logs and record history
Who changed what, and when, is retained on the record. Archive and restore mean a deletion is recoverable rather than final.
Encrypted in transit
All traffic is served over TLS, including client portals and API requests. Credentials are hashed and are never stored in readable form.
Automated backups
Databases are backed up on an automated schedule with point-in-time recovery, and restores are tested rather than assumed to work.
Error monitoring
Application errors are captured and alerted on, so faults are usually found by us before they are reported by you.
Scoped API credentials
API keys are issued per integration and revoked individually. Webhook deliveries and integration failures are logged for review.
Your data stays exportable
Every core record type exports on demand. There is no mechanism designed to make leaving slow or expensive.
What SDRBO is responsible for
- Keeping each workspace’s data in its own database
- Serving all traffic over encrypted connections
- Running and testing automated backups
- Patching the platform, with fixes reaching every workspace at once
- Monitoring for errors and responding to faults
- Recording changes in the audit log without exception
- Telling you promptly and in plain language if something goes wrong
What your administrators control
- Who has a login, and removing people when they leave
- Which roles can see pay rates, financials and customer data
- What the client portal exposes to external users
- Which integrations hold an API key, and revoking unused ones
- Password hygiene and account sharing inside your team
- What data you choose to store in the first place
Whose data is it
Yours. SDRBO stores and processes business records on your behalf. We do not sell them, rent them, or mine them for anything.
- Customer records are not used to train third-party AI models
- Payment processing runs through your own connected processor account, so we never hold your funds
- Exports are available for the life of the subscription and on cancellation
- Deleted records follow a documented retention window and are then removed
- We do not sell or share contact data with advertisers or data brokers, at any price tier
The questions procurement always asks
Short answers you can paste into a vendor review. If your questionnaire needs more detail than this, send it over and we will complete it properly.
| Question | Answer |
|---|---|
| Is our data isolated from other customers? | Yes. One database per workspace, not a shared table. |
| Is data encrypted in transit? | Yes. TLS on all traffic, including portals and API. |
| Are passwords stored in readable form? | No. Credentials are hashed. |
| Do you keep an audit trail? | Yes. Included on every plan, no upgrade required. |
| Can access be restricted by role? | Yes. Record, field and action level, on every plan. |
| Are backups automated? | Yes, on a schedule, with point-in-time recovery. |
| Can we export all of our data? | Yes. Every core record type, on demand, at any time. |
| Is our data used to train AI models? | No. |
| Do you hold customer payment funds? | No. Payments run through your own processor account. |
| Do you hold SOC 2 or ISO 27001? | Not currently. See the status note below. |
| Do you publish an uptime SLA percentage? | Not yet. Contractual terms are discussed for larger deployments. |
| Who are your subprocessors? | Hosting, transactional email and error monitoring. Current list on request. |
Where we are today
SDRBO is a young platform and we would rather be exact than impressive. We do not currently hold a SOC 2 Type II or ISO 27001 attestation, and we will say so on a security questionnaire rather than answer around it. We also do not publish an uptime percentage we have not measured over a meaningful period.
If a formal audit or a contractual availability commitment is a requirement for your business, raise it during evaluation. You will get a straight answer about what exists now and what is realistic on what timeline, instead of a maybe that turns into a no after you have signed.
If something goes wrong
You will hear it from us. Our commitment is direct notification to affected workspace administrators, in plain language, describing what happened, what data was involved, what we did about it and what you should do. No status page euphemisms, and no waiting until a customer notices first.
To report a suspected vulnerability, email security@sdrbo.com. Reports are welcome from anyone, we will confirm receipt, and we will not pursue researchers acting in good faith.
Send us the questionnaire
Whatever your review process requires, send it through and we will complete it honestly, including the sections where the answer is not yet yes.