Trust & security

Built so procurement can say yes.

Everything your client’s procurement team will ask for, on one page you can forward. Detailed enough for their IT review, plain enough to read in a minute.

Image placeholder

Security and trust: encryption, access control, and compliance

Data protection

Where your data lives, and what protects it.

Encryption

TLS 1.2+ in transit. AES-256 at rest. Per-tenant key isolation on Enterprise.

Data residency

Primary region: Australia (Sydney). New Zealand residency available on Enterprise. EU residency on the roadmap.

Backups & recovery

Daily snapshots, 30-day retention. Quarterly restore drills. RPO 24h / RTO 4h on standard; tighter on Enterprise.

Tenant isolation

Logical separation per workspace. Row-level controls on every shared table. No cross-tenant access paths.

Access control

Right people, right scope.

Roles & permissions

Admin, manager, staff, contractor, and read-only roles. Granular per-site overrides for contractors.

Single sign-on (SSO)

SAML 2.0 and OIDC on Enterprise. Google and Microsoft sign-in on every plan.

Audit trail

Every change to a job, site, customer, or contract is logged with actor, timestamp, and before/after value.

Session controls

Configurable session timeout, forced re-auth on sensitive actions, and admin-initiated revoke.

Compliance

Frameworks we operate under.

SOC 2 Type II

In progress. Pre-readiness audit complete; full audit underway with target completion in the next reporting cycle. Letter of attestation available to enterprise prospects on request.

Australian Privacy Act

We comply with the 13 Australian Privacy Principles. Privacy contact: privacy@squadly.io.

GDPR readiness

Data processing agreement (DPA) available. Subject access and erasure requests handled within statutory windows.

Industry frameworks

We engage with ISSA, FMA, BSCAA, and TEFMA on the standards that govern cleaning and FM operations.

Reliability

Uptime, status, and incident handling.

Service availability

99.9% uptime target. Standard plans operate on best-effort; Enterprise customers receive a contractual SLA with service credits.

Status page

Live service status is published at status.squadly.io. Email subscribers notified on incidents within 15 minutes.

Incident response

On-call engineering 24/7. Customer notification on incidents affecting data integrity within 1 hour of detection.

Penetration testing

Independent third-party penetration test annually. Summary report available to enterprise prospects under NDA.

For procurement

What we can sign.

Procurement-ready paperwork

Master Services Agreement (MSA), Data Processing Agreement (DPA), and standard infosec questionnaire responses available on request.

  • MSA template
  • DPA template
  • InfoSec questionnaire pre-completed (CAIQ-lite, VSA-lite)
  • SOC 2 letter of attestation (on request)
  • Penetration test summary (under NDA)
Responsible disclosure

Found a vulnerability? Tell us.

We take security reports seriously and will investigate every credible submission. We ask that you give us reasonable time to address issues before public disclosure.

How to report

Email security@squadly.io with a description of the vulnerability, the steps to reproduce it, and the potential impact. We will acknowledge your report within 24 hours and aim to provide a remediation timeline within 5 business days.

Scope

In scope: app.squadly.io, api.squadly.io, mySquadly mobile apps. Out of scope: third-party services we integrate with, social engineering attacks, physical access attacks, and denial-of-service attacks.

Safe harbour

We will not pursue legal action against researchers who discover and disclose security vulnerabilities responsibly. We ask that you do not access, modify, or delete customer data beyond what is needed to demonstrate the issue.

Bug bounty

We offer recognition and our thanks for valid reports. A formal bounty programme is on our roadmap. High-severity findings may be eligible for discretionary rewards.

Questions

Security contacts.

Security enquiries

For questions about our security posture, architecture, or to request security documentation for procurement: security@squadly.io

Privacy enquiries

For data privacy, access requests, or GDPR/Privacy Act questions: privacy@squadly.io, or see our Privacy Policy.

Urgent incidents

If you have detected an active security incident affecting your Squadly workspace, contact support@squadly.io and mark your subject line URGENT SECURITY.

Choose your path

Start free or evaluate the full platform

Upgrade your team’swork chat

Upgrade your work communications today.It’s free for your entire business.

Get a producttour

Keen to learn more about how Squadly can elevateyour business operations? Book a call.