Security

Company records stay behind company access.

CMD Ops checks the signed-in user, company membership, role, work view, feature access, and requested record before returning company data.

Separate company data

Jobs, employees, hours, schedules, materials, documents, events, and billing records carry a company boundary. Database row rules restrict access to authorized company members.

Roles and work views

Owners, administrators, managers, field leads, employees, and viewers have different permissions. Office and field screens are checked separately from paid-feature access.

Protected accounts

Registration, sign-in, recovery, and persistent sessions use managed authentication. App routes require a valid signed-in session before company data loads.

Restricted files

File paths include the company boundary. A signed-in user must be allowed to see the linked company or job record before opening a protected file.

Location by consent

Live employee location requires the paid capability and employee consent. The client is designed to collect only during an open shift, pause during lunch, and stop after clock-out. Paid activation waits for the matching server-side boundary and retention deletion to pass acceptance.

Server-side checks

The browser does not decide who owns a record. Database functions and row policies re-check company membership, role, and feature access.

Audited admin changes

Platform administration is limited to approved administrators. Company-status and paid-feature changes create audit records.

No zero-risk promise

No online system can promise zero risk. CMD Ops uses layered access controls, keeps the application private from search indexing, and reviews security findings as the product changes.

Report a concern

Send enough detail to investigate without emailing passwords or private keys.

Report a suspected security problem to hello@retehost.com. Include the affected screen, approximate time, and what you observed. Do not send passwords, recovery codes, API keys, or unnecessary customer information.