Upgrade your team’swork chat
Upgrade your work communications today.It’s free for your entire business.
Everything your client’s procurement team will ask for, on one page you can forward. Detailed enough for their IT review, plain enough to read in a minute.
Security and trust: encryption, access control, and compliance
TLS 1.2+ in transit. AES-256 at rest. Per-tenant key isolation on Enterprise.
Primary region: Australia (Sydney). New Zealand residency available on Enterprise. EU residency on the roadmap.
Daily snapshots, 30-day retention. Quarterly restore drills. RPO 24h / RTO 4h on standard; tighter on Enterprise.
Logical separation per workspace. Row-level controls on every shared table. No cross-tenant access paths.
Admin, manager, staff, contractor, and read-only roles. Granular per-site overrides for contractors.
SAML 2.0 and OIDC on Enterprise. Google and Microsoft sign-in on every plan.
Every change to a job, site, customer, or contract is logged with actor, timestamp, and before/after value.
Configurable session timeout, forced re-auth on sensitive actions, and admin-initiated revoke.
In progress. Pre-readiness audit complete; full audit underway with target completion in the next reporting cycle. Letter of attestation available to enterprise prospects on request.
We comply with the 13 Australian Privacy Principles. Privacy contact: privacy@squadly.io.
Data processing agreement (DPA) available. Subject access and erasure requests handled within statutory windows.
We engage with ISSA, FMA, BSCAA, and TEFMA on the standards that govern cleaning and FM operations.
99.9% uptime target. Standard plans operate on best-effort; Enterprise customers receive a contractual SLA with service credits.
Live service status is published at status.squadly.io. Email subscribers notified on incidents within 15 minutes.
On-call engineering 24/7. Customer notification on incidents affecting data integrity within 1 hour of detection.
Independent third-party penetration test annually. Summary report available to enterprise prospects under NDA.
Master Services Agreement (MSA), Data Processing Agreement (DPA), and standard infosec questionnaire responses available on request.
We take security reports seriously and will investigate every credible submission. We ask that you give us reasonable time to address issues before public disclosure.
Email security@squadly.io with a description of the vulnerability, the steps to reproduce it, and the potential impact. We will acknowledge your report within 24 hours and aim to provide a remediation timeline within 5 business days.
In scope: app.squadly.io, api.squadly.io, mySquadly mobile apps. Out of scope: third-party services we integrate with, social engineering attacks, physical access attacks, and denial-of-service attacks.
We will not pursue legal action against researchers who discover and disclose security vulnerabilities responsibly. We ask that you do not access, modify, or delete customer data beyond what is needed to demonstrate the issue.
We offer recognition and our thanks for valid reports. A formal bounty programme is on our roadmap. High-severity findings may be eligible for discretionary rewards.
For questions about our security posture, architecture, or to request security documentation for procurement: security@squadly.io
For data privacy, access requests, or GDPR/Privacy Act questions: privacy@squadly.io, or see our Privacy Policy.
If you have detected an active security incident affecting your Squadly workspace, contact support@squadly.io and mark your subject line URGENT SECURITY.
Upgrade your work communications today.It’s free for your entire business.
Keen to learn more about how Squadly can elevateyour business operations? Book a call.