Security
How your evidence is protected
Site photos, owner documents and signed reports are confidential client material. This page says, in plain terms, what we do with them. The binding commitments are in the Data Processing Addendum, the AI Disclosure and the Subprocessor List.
Where your data lives
- The application runs on Vercel and the database and file storage on Supabase, both in the United States (Virginia).
- Everything is encrypted in transit (TLS) and at rest by the providers. Files sit in a private bucket; nothing is publicly listable.
- The database provider takes daily encrypted backups.
Who can see it
- Every row and every file belongs to one firm, and every read is filtered by the signed-in firm. One firm cannot reach another's jobs.
- Row-level security is on for every table, so the providers' public data interfaces return nothing; only our server can read the database.
- Sign-in is handled by Clerk. We never store passwords, and multi-factor authentication is available to every user.
- Production access is limited to the people who operate the Service, through provider accounts protected by multi-factor authentication, and is used only to run, support and repair it.
Uploads, links and delivery
- Photos and documents go straight to private storage through signed, short-lived upload URLs issued one file at a time; the server checks the file type and size before issuing one.
- Share links use long random tokens, expire after 30 days and can be revoked at once from the report page.
- Payments are handled by Stripe. We never see or store card numbers.
The AI
- Evidence is sent to the model from our servers only, never from your browser.
- Every request goes to Anthropic through Vercel's AI Gateway with two requirements attached: zero data retention and no training. The gateway refuses to route a request to a provider that does not meet both.
- Text inside uploaded documents is treated as data, never as instructions, and every model output is validated against a fixed schema before it is used.
Records and control
- An audit log records the actions taken in your workspace. Errors are recorded and alerted to us without your evidence in them.
- Public endpoints are rate-limited.
- An owner can download everything as one zip, delete any job permanently, or close the workspace (deleted for good 30 days later) without asking us.
If something goes wrong
- We follow a written incident-response procedure and notify affected customers without undue delay, and within 72 hours of confirming a breach of their data.
- Report a vulnerability to security@baselinepcr.com. We acknowledge within two business days and will not pursue good-faith research that avoids other customers' data and service disruption.
Questions from your client's IT or compliance team: security@baselinepcr.com.