Legal
Inspection records are evidence. Auditmark treats security as a design constraint, not a feature tier.
Every organization's data is isolated at the database layer with row-level security. Isolation is enforced on every query by the database itself, not filtered in application code, so a bug in a screen cannot leak another organization's data. The same boundary holds inside AI features: only the calling organization's data can enter a request, and output referencing anything else is rejected.
All traffic between devices and Auditmark uses TLS, including offline sync when a device reconnects. Data at rest, including photos and signatures, is encrypted on managed database and file storage.
Your administrators decide who belongs to your organization and what each role can do; the server enforces those permissions on every request, and denied actions stay denied even if a client misbehaves. Inside Auditmark, production access is limited to named staff on a least-privilege basis and is logged.
AI features are off until an organization enables them. Every AI response is forced into a strict schema and validated server-side before it can touch data, so a manipulated prompt cannot produce a privileged action or a cross-organization reference. Customer content sent to the AI provider is not used to train models.
The platform runs in containers with automated, verified deployments and a tested rollback path. Data is backed up automatically, and monitoring with structured error logging surfaces problems early. The field app keeps working offline and syncs when coverage returns, so a connectivity loss does not cost field work.
Auditmark maintains an incident response process and notifies affected customers without undue delay after becoming aware of a personal data breach, as the data processing addendum commits.
If you believe you have found a security issue, email hello@auditmark.io with enough detail to reproduce it. Auditmark confirms receipt, investigates, and keeps you informed. Please do not access data that is not yours while demonstrating an issue.
The contractual commitments live in the data processing addendum, the provider list in the subprocessor list, and data handling in the privacy policy.