Security & privacy at PatrolOS

This page is maintained by PatrolOS to answer common security and privacy questions about our platform. It describes controls that are enabled today; it is not an independent certification.

Encryption in transit & at rest

All traffic uses TLS 1.2+. Data at rest is encrypted with AES-256 by the managed database provider.

Role-based access control

Row-level security scopes every read and write to the signed-in user's organization and role.

Least-privilege authentication

Supabase-managed auth with email + OAuth. Administrators can require MFA per organization.

Managed, monitored infrastructure

Hosted on Cloudflare and Supabase infrastructure with automatic backups and 24/7 monitoring.

Audit logging

Sensitive actions (role changes, data exports, checkpoint edits) are written to an append-only audit log.

Incident response

We investigate reported security issues within one business day. Report to angel18almanza@gmail.com.

Subprocessors

Third parties that process customer data on our behalf.

  • SupabaseDatabase, authentication, storage
  • CloudflareApplication hosting and CDN
  • Lovable AI GatewayAI model inference for Copilot
  • ResendTransactional email

Data handling

  • • Customer data is scoped to your organization via row-level security.
  • • Photos, video, and voice recordings are stored in encrypted object storage.
  • • Data is retained for the life of your subscription. On request we delete within 30 days.
  • • You can export your data at any time from Settings → Billing.

Privacy requests

Data subject requests (access, deletion, portability) can be submitted to angel18almanza@gmail.com. We respond within 30 days as required by GDPR and CCPA.

Certifications

PatrolOS holds no third-party security certification today. We do not claim SOC 2, ISO 27001, HIPAA, or PCI compliance, and we will only say otherwise here once an independent report exists. What we do describe on this page are the controls that are actually live in the product.

  • Live today
    Role-based access control, row-level tenant isolation, encryption in transit and at rest by our managed providers, audit logging of sensitive actions, and managed backups.
  • Not available
    Independent audit reports, SSO/SAML, and signed BAAs are not offered at this time.

This page is maintained by PatrolOS and is not independent verification. Security questionnaires are answered on request — see our legal documents for data processing terms.

Reporting a vulnerability

Please email angel18almanza@gmail.com with a description of the issue and reproduction steps. We acknowledge reports within one business day.

Need a DPA or security questionnaire?

Enterprise customers can request a signed Data Processing Agreement, complete a security questionnaire, or schedule a review call with our team.

Contact our team