Security and privacy
How ProTTM protects your records
Protection
What's in place
Separate company data
- Each company's records are separated by row-level security in the PostgreSQL database, not only on screen.
- The app connects as a database user that can't bypass that separation. Every request runs inside one company.
- Files such as plans, photos and email attachments only open after a check that the person can see the record they belong to.
Sign-in
- Passwords are at least 10 characters and stored only as Argon2 hashes. Email addresses are confirmed before first use.
- Two-factor sign-in with an authenticator app and backup codes. Require it for everyone or for chosen roles. Nothing else opens until it's set up.
- Sign-in, code and password-reset attempts are rate-limited. Resetting a password signs the account out everywhere.
- Sessions end after 14 days without use. Sensitive changes need a sign-in within the last 15 minutes. Email sign-in links are off for accounts with two-factor.
Roles and permissions
- Each permission covers a person's own work, their team, a business unit or the whole company.
- Field workers and subcontractors see only their own jobs, shifts, timesheets and forms.
- Menus and buttons show only what a role allows, and the server checks every action again.
- Costs and margins need their own permission. No one can grant more access than they have.
Audit log
- The database records every change: who, when, and the values before and after.
- The app can't write to or alter that history. Passwords and tokens are never logged, only the fact that one changed.
- Administrators can view the audit log and export it to CSV.
Secrets and keys
- Xero tokens are stored encrypted with AES-256-GCM.
- API keys are shown once and stored only as a fingerprint, so a lost key is replaced, never recovered.
- Read-only share links for inspection reports store only a fingerprint of their token.
Integrations
- The read-only API can't change data. Each key has its own scopes, is limited to 120 calls a minute and 20,000 a day, and every call is logged.
- Xero is connected with OAuth and PKCE, and Xero's webhooks are checked against their signature.
Email
- ProTTM sends only account emails: invitations, password resets, email confirmations and sign-in links. It never emails your clients.
- Email sent to a task's address is cleaned before anyone sees it. Scripts and forms are removed, and remote images (including tracking pixels) stay blocked until someone shows them. Risky attachments such as .exe files aren't kept.
Support access
- If ProTTM support needs to see what you see, a platform administrator can open a 30-minute session as that person, with a recorded reason.
- Document sign-offs are off during that session. Any change made in it shows in your audit log with the support person's name.
This website
Privacy on this website
This website doesn't use cookies, analytics or advertising trackers.
The Book a demo form stores what you enter, your consent, and a one-way code made from your internet address to stop repeat submissions. It isn't emailed anywhere or added to a mailing list.
Questions
Security questions
Where is our data held?
In ProTTM's PostgreSQL database. Each company's records are separated by row-level security in the database itself, not only on screen.
Files such as plans, photos and email attachments only open after a check that the person can see the record they belong to. Ask us for the hosting provider and region.
How are sign-ins protected?
Passwords must be at least 10 characters and are stored only as Argon2 hashes. Two-factor sign-in uses an authenticator app with backup codes, and you can require it for everyone or for chosen roles.
Repeated sign-in and code attempts are rate-limited. Resetting a password signs the account out everywhere.
Is there an audit trail?
Yes. The database records every change: who made it, when, and the values before and after. The app can't alter that history. Administrators can view the audit log and export it to CSV.
Can we get our data out?
Yes. Reports download as CSV or Excel. Lists such as the competency matrix and audit log export to CSV. The read-only API returns your tasks, TMPs, bookings, timesheets and invoices.