Trust

Security and Trust

How Pillar protects company data, connected financial information, and access across every workspace.

Tenant isolated

Company data is scoped to its own workspace.

Access controlled

Authentication, roles, and server-side checks protect sensitive workflows.

Server-side safeguards

Sensitive platform credentials stay out of browser code.

Pillar OS is designed for construction companies that manage sales, projects, client communications, financial workflows, approvals, documents, and day-to-day operations. We understand this data can include confidential business, client, vendor, subcontractor, pricing, payment, and project information.

This page summarizes our current trust and security approach. It is intended to be practical and transparent, not a complete security audit or legal agreement. Security practices may evolve as the platform grows.

Tenant Isolation

Each company account is treated as a separate tenant. Customer data is scoped by company account, and access to company records is limited based on authorized users, roles, permissions, and application-level controls.

The platform is designed so authenticated users should only access the company workspace and data they are authorized to view. Tenant-scoped records are protected through database-level row security and server-side application checks that derive the user's company from the authenticated session.

Public client-facing links, such as proposals, approvals, payments, signatures, portals, and field-log requests, are designed to use unguessable tokens or parent records instead of exposing a customer workspace directly.

Account Access and User Permissions

Customers are responsible for managing their own team members, user access, permissions, internal approvals, and business controls.

Each customer should only invite authorized employees, contractors, or representatives who need access to the platform. Customers are responsible for removing access when a team member no longer needs it.

Customers are also responsible for protecting login credentials, using strong passwords, securing devices, and making sure users follow the customer's internal policies for handling client, financial, and project data.

Platform Owner Access

Pillar OS may access customer accounts or data when necessary for support, onboarding, troubleshooting, billing, security, product improvement, customer success, or legal compliance.

Platform owner access is limited to legitimate business purposes. Internal access is intended to be restricted to authorized personnel and used only when needed to provide, support, secure, maintain, improve, or administer the platform.

Server-Side Secrets

Sensitive platform credentials, including payment processor keys, service-role keys, AI provider keys, email provider keys, and integration credentials, are intended to remain server-side and should not be exposed in browser code.

Data Protection and Application Controls

Pillar OS uses reasonable administrative, technical, and organizational safeguards intended to protect customer data from unauthorized access, loss, misuse, alteration, or disclosure.

Current safeguards may include authenticated access, tenant-scoped database rules, server-side authorization, encrypted transport where supported by providers, private storage for sensitive documents, production environment separation, secret management through hosting and provider controls, logging, monitoring, and operational review of sensitive workflows.

However, no software platform, hosting provider, database, storage system, network, internet transmission, or electronic communication can be guaranteed to be completely secure.

Construction and Financial Data

Customer data may include leads, client records, addresses, proposals, project files, field logs, invoices, expenses, payment metadata, approval records, subcontractor information, vendor information, uploaded photos, documents, messages, and business notes.

Pillar OS is designed to help organize this information, but customers remain responsible for the accuracy of their records, internal approvals, financial review, tax treatment, payroll decisions, contractor licensing, client communications, and construction compliance.

Plaid access tokens are encrypted at rest and are not exposed to browser clients. Connected-bank routes require Owner access, server-derived tenant scope, and multi-factor authentication. Bank credentials are entered through Plaid and are not received or stored by Pillar OS.

Third-Party Providers

Pillar OS may rely on third-party providers for hosting, authentication, payments, email, storage, analytics, artificial intelligence, and other platform services.

These providers may process customer data only as needed to support the platform and related services. Depending on the customer's use of the platform, subprocessors may include infrastructure, database, authentication, payment, communications, file storage, analytics, error monitoring, and AI providers.

We expect subprocessors to provide appropriate security and confidentiality commitments for the services they perform. Specific provider lists may change over time as the platform evolves or as features are added, replaced, or retired.

AI Features

AI features may assist with summaries, drafts, workflows, project notes, financial organization, and other operational tasks. AI-generated content may be incomplete, inaccurate, or require human review.

Customers are responsible for reviewing AI outputs before using them for business, legal, financial, client-facing, or operational decisions.

When AI features are used, relevant customer data may be processed by third-party AI providers or internal AI systems to complete the requested workflow. Customers should avoid entering unnecessary sensitive personal data into AI prompts and should verify all generated scopes, estimates, messages, summaries, and financial notes before use.

Customer Data Ownership

Customers retain ownership of the business data they submit into Pillar OS.

Pillar OS does not claim ownership over customer project records, client information, documents, estimates, invoices, expenses, or other business data uploaded or entered into the platform.

We use customer data to provide, support, secure, maintain, improve, and operate the platform, or as otherwise permitted by agreement, law, or customer instruction.

Data Retention, Export, and Offboarding

Customer data may be retained while an account is active and for a reasonable period after cancellation, suspension, or termination.

Upon cancellation or offboarding, customers may request a reasonable export of their business data, subject to technical limitations, account status, payment status, legal obligations, and platform policies.

Pillar OS may retain certain records where necessary for backup, audit, billing, security, legal, tax, fraud prevention, or legitimate business purposes.

Backup copies and provider logs may remain for a limited period according to normal backup, security, and retention cycles. Deletion requests may be limited where retention is required for legal, billing, tax, audit, dispute, fraud prevention, security, or compliance reasons.

Availability and Change Management

Pillar OS uses reasonable efforts to keep the platform available and functioning. The platform may still be unavailable because of maintenance, deployment, provider outages, internet issues, security events, or other circumstances outside our control.

Production changes are intended to follow review, environment checks, and deployment verification appropriate to the current stage of the business. Some features may be pilot, beta, limited release, or subject to change.

Security Limitations

This page does not represent that Pillar OS currently holds any specific security certification, audit report, compliance attestation, or regulated-industry authorization unless separately stated in writing.

Customers with specific legal, insurance, procurement, data processing, or compliance requirements should review those requirements with their own advisors before using the platform for regulated or highly sensitive data.

Incident Reporting

If you believe you found a security issue, unauthorized access, suspicious account activity, exposed data, or a vulnerability affecting Pillar OS, contact us immediately at:

security@pillaros.app

Please include a clear description, affected account or URL if applicable, steps to reproduce if safe to share, and your contact information. Do not access, modify, delete, download, or disclose data that does not belong to you.