Trust

Every business's data stays its own.

This page describes SET's actual architecture, not aspirational claims. Where something is not built yet, it says so.

Tenant isolation
Every table that holds business data has row-level security enabled and enforced by Postgres itself — not just application logic. A business's data is scoped to that business at the database layer, the same layer that would have to be compromised to bypass it.
Location-scoped permissions
A multi-location business can scope a staff member to specific locations. That scope is enforced server-side against the authenticated session — never trusted from a URL parameter or client-supplied value.
Private file storage
Photos and documents attached to work live in a private storage bucket. There is no public bucket and no raw path exposure — every file is reached through a short-lived signed URL, generated only after a server-side authorization check.
Hashed, capability-scoped links
Booking, tracking, and appointment-management links use randomly generated tokens. Only a hash of the token is ever stored — the raw token exists for a moment at issue time and is never recoverable from the database afterward. Each link is scoped to specific capabilities (view, approve, reschedule) rather than granting blanket access.
Rate-limited booking, requests and Points
Public booking, guest requests, and SET Point lookups are metered server-side against shared state, independent of any browser-side control an attacker could bypass. Tracking-link lookups are the exception: they are still throttled per server instance, and moving them onto the same shared limit is outstanding work rather than something this page will imply is done.
No guesswork identity matching
A contact detail is never an identity key: a public booking is never attached to an existing customer because a phone number or email happened to match. An inbound reply is attributed only when exactly one customer in that business matches the sending number — if none or several do, SET stores that a message arrived and refuses to guess whose it was, keeping the body out of the record entirely.

What SET does not claim

SET is not SOC 2 certified, HIPAA compliant, or ISO certified. There are no published uptime figures and no customer references, because SET is in a pilot and neither exists yet. If a formal certification matters for your business, raise it directly rather than relying on this page as a substitute.

Questions about security or a specific requirement? Reach us at security@teset.app.