Security and reliability

Your data, in your own database.

SDRBO uses single-tenant isolation. Each customer workspace runs against its own database instead of sharing tables with every other account. Combined with role-based permissions and audit logging on every plan, that turns access questions into something you can answer with facts rather than assurances.

1:1One database per workspace
Every planRoles, permissions and audit logs
Any timeFull export of your records
Where a record livesIsolation path
  1. Request over TLSEncrypted in transit, always
  2. Authenticated sessionCredentials hashed, never stored readable
  3. Role and permission checkRecord, field and action level
  4. Your workspace databaseNot a shared table filtered by account
  5. Write recorded in the audit logWho changed what, and when
  6. Backed up on schedulePoint-in-time recovery
No shared table. No cross-account query path.
Controls

How the platform is protected

Every item here is included at every price. Security is not a tier, because charging for it would mean selling the safe version of the product separately from the cheap one.

Isolated data per customer

Each workspace has a dedicated database. There is no shared table where a missing filter in one query could expose another company’s records.

Roles and permissions everywhere

Restrict records, fields and actions by role. Sensitive areas such as pay rates and workforce records can be limited to named administrators on any plan.

Audit logs and record history

Who changed what, and when, is retained on the record. Archive and restore mean a deletion is recoverable rather than final.

Encrypted in transit

All traffic is served over TLS, including client portals and API requests. Credentials are hashed and are never stored in readable form.

Automated backups

Databases are backed up on an automated schedule with point-in-time recovery, and restores are tested rather than assumed to work.

Error monitoring

Application errors are captured and alerted on, so faults are usually found by us before they are reported by you.

Scoped API credentials

API keys are issued per integration and revoked individually. Webhook deliveries and integration failures are logged for review.

Your data stays exportable

Every core record type exports on demand. There is no mechanism designed to make leaving slow or expensive.

Our side

What SDRBO is responsible for

  • Keeping each workspace’s data in its own database
  • Serving all traffic over encrypted connections
  • Running and testing automated backups
  • Patching the platform, with fixes reaching every workspace at once
  • Monitoring for errors and responding to faults
  • Recording changes in the audit log without exception
  • Telling you promptly and in plain language if something goes wrong
Your side

What your administrators control

  • Who has a login, and removing people when they leave
  • Which roles can see pay rates, financials and customer data
  • What the client portal exposes to external users
  • Which integrations hold an API key, and revoking unused ones
  • Password hygiene and account sharing inside your team
  • What data you choose to store in the first place
Ownership

Whose data is it

Yours. SDRBO stores and processes business records on your behalf. We do not sell them, rent them, or mine them for anything.

  • Customer records are not used to train third-party AI models
  • Payment processing runs through your own connected processor account, so we never hold your funds
  • Exports are available for the life of the subscription and on cancellation
  • Deleted records follow a documented retention window and are then removed
  • We do not sell or share contact data with advertisers or data brokers, at any price tier
If a feature would require selling your customer list to fund it, we would rather not build the feature.
Quick answers

The questions procurement always asks

Short answers you can paste into a vendor review. If your questionnaire needs more detail than this, send it over and we will complete it properly.

Common vendor security questions and SDRBO’s answers
QuestionAnswer
Is our data isolated from other customers?Yes. One database per workspace, not a shared table.
Is data encrypted in transit?Yes. TLS on all traffic, including portals and API.
Are passwords stored in readable form?No. Credentials are hashed.
Do you keep an audit trail?Yes. Included on every plan, no upgrade required.
Can access be restricted by role?Yes. Record, field and action level, on every plan.
Are backups automated?Yes, on a schedule, with point-in-time recovery.
Can we export all of our data?Yes. Every core record type, on demand, at any time.
Is our data used to train AI models?No.
Do you hold customer payment funds?No. Payments run through your own processor account.
Do you hold SOC 2 or ISO 27001?Not currently. See the status note below.
Do you publish an uptime SLA percentage?Not yet. Contractual terms are discussed for larger deployments.
Who are your subprocessors?Hosting, transactional email and error monitoring. Current list on request.
Status

Where we are today

SDRBO is a young platform and we would rather be exact than impressive. We do not currently hold a SOC 2 Type II or ISO 27001 attestation, and we will say so on a security questionnaire rather than answer around it. We also do not publish an uptime percentage we have not measured over a meaningful period.

If a formal audit or a contractual availability commitment is a requirement for your business, raise it during evaluation. You will get a straight answer about what exists now and what is realistic on what timeline, instead of a maybe that turns into a no after you have signed.

If something goes wrong

You will hear it from us. Our commitment is direct notification to affected workspace administrators, in plain language, describing what happened, what data was involved, what we did about it and what you should do. No status page euphemisms, and no waiting until a customer notices first.

To report a suspected vulnerability, email security@sdrbo.com. Reports are welcome from anyone, we will confirm receipt, and we will not pursue researchers acting in good faith.

Send us the questionnaire

Whatever your review process requires, send it through and we will complete it honestly, including the sections where the answer is not yet yes.