JobQuoteFlow

SECURITY

Security at JobQuoteFlow

Transport and browser security

JobQuoteFlow is served over HTTPS. The production site uses HSTS, content-security, frame-blocking, MIME-sniffing protection, a restrictive permissions policy and a strict referrer policy.

Account credentials

Passwords are not stored in plain text. The application derives password hashes using PBKDF2 with a per-password salt before saving account credentials.

Proposal links and customer data

Customer proposal links act as access tokens and should be treated as confidential. Product analytics are designed to exclude proposal tokens, passwords, customer contact details, free-form quote content and exact quote values.

Scope

This page describes implemented safeguards; it is not a claim of SOC 2, ISO 27001 or other third-party certification. Report suspected security issues through the contact form without including secrets.