Trust
Every business's data stays its own.
This page describes SET's actual architecture, not aspirational claims. Where something is not built yet, it says so.
- Tenant isolation
- Every table that holds business data has row-level security enabled and enforced by Postgres itself — not just application logic. A business's data is scoped to that business at the database layer, the same layer that would have to be compromised to bypass it.
- Location-scoped permissions
- A multi-location business can scope a staff member to specific locations. That scope is enforced server-side against the authenticated session — never trusted from a URL parameter or client-supplied value.
- Private file storage
- Photos and documents attached to work live in a private storage bucket. There is no public bucket and no raw path exposure — every file is reached through a short-lived signed URL, generated only after a server-side authorization check.
- Hashed, capability-scoped links
- Booking, tracking, and appointment-management links use randomly generated tokens. Only a hash of the token is ever stored — the raw token exists for a moment at issue time and is never recoverable from the database afterward. Each link is scoped to specific capabilities (view, approve, reschedule) rather than granting blanket access.
- Rate-limited booking, requests and Points
- Public booking, guest requests, and SET Point lookups are metered server-side against shared state, independent of any browser-side control an attacker could bypass. Tracking-link lookups are the exception: they are still throttled per server instance, and moving them onto the same shared limit is outstanding work rather than something this page will imply is done.
- No guesswork identity matching
- A contact detail is never an identity key: a public booking is never attached to an existing customer because a phone number or email happened to match. An inbound reply is attributed only when exactly one customer in that business matches the sending number — if none or several do, SET stores that a message arrived and refuses to guess whose it was, keeping the body out of the record entirely.
What SET does not claim
SET is not SOC 2 certified, HIPAA compliant, or ISO certified. There are no published uptime figures and no customer references, because SET is in a pilot and neither exists yet. If a formal certification matters for your business, raise it directly rather than relying on this page as a substitute.
Questions about security or a specific requirement? Reach us at security@teset.app.