Tenant and access safeguards
- Business records use explicit organization ownership in a shared PostgreSQL schema.
- Request lookups begin from the authenticated user’s verified organization, and authorization is based on that organization membership.
- Passwords are stored as password hashes, not readable passwords. Production sessions use signed, HttpOnly, SameSite cookies sent only over HTTPS.
- Public quotes and issued invoices use revocable, unguessable tokens and customer-safe allowlisted views. Sequential database IDs are not public-document credentials.
- Jobs handling tenant records receive organization and record identifiers and reload through that organization.
Data and financial integrity
Money is stored in integer cents. Quote and invoice line items preserve description, price, discount, and tax snapshots. Document numbers are allocated under database locks and protected by organization-scoped unique constraints. Payment updates and quote-to-invoice conversion use transactions. Issued invoices and payment history are protected from casual deletion.
BayLedger subscription checkout and billing management use Stripe-hosted pages. BayLedger stores provider identifiers and subscription state needed to administer each organization, but not complete payment-card details. Signed Stripe events are verified and reloaded from the provider before they can update one organization’s billing state. Subscription access and seat counts are applied per organization; owners retain billing, export, and support recovery access when ordinary access is restricted.
Uploads and customer documents
Organization logos and private vehicle photos accept validated PNG, JPEG, or WebP images up to 5 MB and reject scriptable formats. Logos are available only to authorized shop users or through the secure public document they belong to. Vehicle photos are available only to signed-in members of their organization and are not exposed through customer-facing quote or invoice links. Quotes and invoices use printable web views; BayLedger does not currently generate downloadable PDFs.
Service infrastructure
BayLedger relies on reputable third-party providers for hosting, encrypted web connections, email delivery, and subscription billing. Access to production systems is restricted, and operational changes follow documented deployment and recovery procedures.
The service does not currently claim high availability or uninterrupted operation. An interruption or failure affecting BayLedger or one of its providers may affect access to the service.
Backups and recovery
BayLedger maintains regular backups of production data as part of our service-continuity and recovery procedures. Backup copies are stored separately from the primary production system and are periodically tested for recoverability.
While we maintain safeguards intended to protect customer data and restore service after an unexpected failure, no backup or recovery system can guarantee complete recovery in every circumstance.
Logging and operations
BayLedger records filtered operational information to diagnose errors and support requests. A request identifier, software release, affected application area, and numeric organization identifier may be included when useful. Passwords, access tokens, session cookies, email bodies, customer notes, payment references, and complete submitted records are excluded by design.
What is not claimed
BayLedger does not currently claim SOC 2, ISO 27001, PCI DSS, or another security certification; a formal penetration test; encryption of every production disk or backup at rest; point-in-time database recovery; uninterrupted availability; a guaranteed recovery point or recovery time; or compliance on behalf of a shop.
Security questions or responsible reports can be sent to documents@bayledger.ca. Do not include exploit payloads against production, personal information, passwords, or active tokens without first arranging a safe channel.