SECURITY
Security at JobQuoteFlow
Transport and browser security
JobQuoteFlow is served over HTTPS. The production site uses HSTS, content-security, frame-blocking, MIME-sniffing protection, a restrictive permissions policy and a strict referrer policy.
Account credentials
Passwords are not stored in plain text. The application derives password hashes using PBKDF2 with a per-password salt before saving account credentials.
Proposal links and customer data
Customer proposal links act as access tokens and should be treated as confidential. Product analytics are designed to exclude proposal tokens, passwords, customer contact details, free-form quote content and exact quote values.
Scope
This page describes implemented safeguards; it is not a claim of SOC 2, ISO 27001 or other third-party certification. Report suspected security issues through the contact form without including secrets.