How we protect your data
Depot holds the records that prove a machine was safe to run — inspections, work orders, the photograph someone took of a cracked weld. If you lose that history you lose the ability to answer a regulator or an insurer. This page describes what we do to protect it, and it describes only what is actually running today.
Where your data is
Your records are stored in Canada. The application database, the files you upload and your sign-in records are held in a Montreal region. Content delivery, telephone call recordings and backups are handled across North America and may be located in the United States.
Every company that processes data on our behalf is named, with what it does and where it operates, on our sub-processor list. We give customers thirty days’ notice by email before a new one starts.
One organization cannot see another’s data
This is the control we care most about, so it is worth saying exactly how it works.
The separation is enforced by the database, not by application code. Every record carries the organization it belongs to, and the database evaluates that on every single query against the identity of whoever is asking. A bug in a screen cannot bypass it, because the screen is not what enforces it. For roles scoped to one branch, the same rule applies again at branch level.
It is checked on every change we make. Automated tests assert that no organization can reach another’s records, and that the anonymous, unauthenticated role holds no access to any application table at all. Those tests run before any change can be merged, and a failure blocks the change rather than raising a warning somebody might miss.
Encryption
Everything is encrypted in transit using TLS, and plain HTTP is redirected rather than served. Your data is encrypted at rest by our infrastructure providers using AES-256, covering the database, the files you upload, and backups. We do not hold the encryption keys ourselves; our providers hold and rotate them.
Signing in
Depot accounts have no passwords. You sign in with a six-digit code sent to your work email, so there is no password for us to store and none for an attacker to steal from us. Anyone can start a new organization by signing up as its administrator, but nobody can join an existing organization on their own: every other account in it is created by that organization’s administrator.
Who at Depot can reach your data
Almost nobody, almost never, and never quietly.
- Our sales staff cannot reach customer data at all. Not restricted — they hold no access record in the database, so there is nothing to misconfigure.
- Support access is temporary and justified. Reaching a customer’s organization requires a stated reason and a ticket reference, is read-only, and expires automatically within an hour. The expiry cannot be extended.
- Every access is recorded, with who, when, which organization and why.
A record of what changed
Changes to business-critical records are written to an audit log that is append-only, enforced by the database itself. Entries cannot be edited or deleted, including by us, and the protection covers the tables that will be created next year as well as the ones that exist now. Changes to who holds elevated access are recorded the same way.
Keeping it running
The database is backed up automatically every day and each backup is kept for seven days.
We watch the service from outside itself. Our monitoring runs on separate infrastructure from the application, so it can still report a problem when the application’s own provider is the problem, and it has a dead-man check so that monitoring falling over is itself detectable.
Our status page is public, and it reports how much of the period we actually measured separately from uptime — so a gap in our monitoring is never presented to you as a healthy hour.
How changes reach production
Every change goes through a pull request and must pass an automated suite — type checks, unit tests, the isolation tests above, and a scan of the full history for accidentally committed credentials.
Nothing reaches production that has not already been deployed and verified in a staging environment first, and what gets promoted is the exact same build, identified by its commit, rather than a rebuild that might differ. After each deployment an automated check confirms the live system still refuses anonymous access.
What we do not do with your data
- We do not sell it, and we do not share it for advertising.
- We run no advertising or analytics cookies on this website and no third-party trackers.
- We do not use your data to train generative AI models.
- We never use one organization’s content to produce output for another.
Independent assurance
A SOC 2 Type II examination is in progress and has not yet been obtained. We will make the report available under confidentiality once it is issued. We would rather tell you that plainly than imply a certification we do not hold.
Our Data Processing Addendum applies automatically to every customer and sets out these measures as contractual commitments, along with our breach-notification obligation and what happens to your data when you leave.
Reporting a security problem
Email [email protected]. Tell us what you found, how to reproduce it, and what it reaches. If it involves customer data, describe the kind of data rather than sending us records.
We acknowledge reports within two business days and give an initial assessment within five. Our Acceptable Use Policy sets out the terms for good-faith security research, including that reporting something in good faith will never get you in trouble with Depot.
Security questions
If you are evaluating Depot and need a security questionnaire completed, a copy of our Data Processing Addendum, or detail this page does not cover, email [email protected].
Contact
Depot Holdings Group, Inc., 14306 Seventh St #100, Dade City, FL 33523 — [email protected].