# Prepared answers to common security questionnaires

These are answers to the questions SIG Lite, CAIQ and manufacturing IT vendor checklists usually ask. They cover the hosted products, Alderworks EMS and the hosted Alderworks Quality Suite. They describe the code as of 2026-09-28 (branch `it-readiness`).

Status marks:
- **[verified]**: checked in the code, the database policies or a local test run.
- **[plan]**: depends on a provider plan or a dashboard setting Alderworks controls. Confirm the current value before quoting it.
- **[no]**: not offered today.

Answer "yes" to a question only where the mark supports it.

Short summary: [security-overview.md](security-overview.md).

---

## 1. Company and compliance

| Question | Answer |
|---|---|
| Legal entity | Alderworks LLC, registered in Illinois, USA. |
| SOC 2 / ISO 27001 / other attestation? | **[no]** None. |
| Penetration test? | **[no]** No external test yet. |
| Subprocessors' attestations | Supabase (database, auth, storage), Vercel (hosting) and Stripe (payments) each publish SOC 2 Type II reports, available from them under NDA. Stripe is PCI DSS Level 1. Resend (email) publishes its own security documentation. |
| Subprocessor list | Published on the Security page and in the privacy policy, generated from one source (`lib/legal.ts`). It lists Supabase, Vercel, Stripe and Resend, and what each receives. **[verified]** |
| Data processing agreement | Available on request. The text is being prepared with counsel. |
| Cyber insurance | Not stated here. Ask. |
| Written security policies (ISMS, acceptable use, etc.) | No formal policy set is published. This document and the Security page describe the controls in place. |

## 2. Identity and access management

| Question | Answer |
|---|---|
| Unique user accounts? | Yes. Every person has their own account (email and password). There are no shared logins. **[verified]** |
| Password storage | One-way hashes, stored by Supabase Auth (bcrypt). Alderworks never sees or stores passwords. **[verified]** (hashing is Supabase's) |
| Password policy | Sign-up, invitation and reset pages require at least 8 characters. **[verified]** The minimum enforced by the sign-in service itself, and leaked-password checking, are project settings. **[plan]** |
| MFA available? | Yes. Two-step sign-in with any TOTP authenticator app, for every user. **[verified]** |
| Can the customer require MFA? | Yes. A workspace admin can require two-step sign-in for all members. The database enforces it: a session without the second step cannot read or change anything in the workspace. Members without it set it up at their next sign-in. Admins can reset it for a lost phone, and the reset is logged. **[verified]** |
| SSO (SAML / OIDC; Entra ID, Google Workspace, Okta) | **[no]** Not yet. The platform supports SAML 2.0 on a paid plan, and Alderworks can enable it per customer on request once that plan is in place. **[plan]** |
| SCIM / automated provisioning | **[no]** Admins add and remove people in the product. |
| Role-based access | EMS: administrator, manager, technician, viewer. Suite: admin, staff. Enforced by server routes and database policies, not just the screens. **[verified]** |
| Least privilege for Alderworks staff | Support access to a workspace is a separate, recorded membership type (platform_support), distinguishable from customer accounts. The database service key is used only by server code. **[verified]** |
| Brute-force protection / lockout | Sign-in attempts are rate-limited per IP address by Supabase Auth. **[plan]** (limits are project settings) The application adds its own limits on invitations, password resets, workspace creation and public routes. **[verified]** Per-account lockout after N failures is not offered; two-step sign-in is the control against password guessing. |
| Session timeout | Access tokens last one hour by default and are renewed while in use. Renewal tokens rotate on use. **[plan]** (project setting) Per workspace, an admin can set idle sign-out from 15 minutes to 8 hours, with a one-minute warning. Activity in any of the workspace's tabs counts. **[verified]** Server-side absolute session lifetime and inactivity timeout are platform settings, not yet set. **[plan]** |
| Sign out everywhere | Yes. The account security page revokes every session of the account. Pages already open elsewhere stop within the hour, when their token expires. **[verified]** |
| Email verification | A workspace is created only for a confirmed email address. **[verified]** |
| Offboarding | Removing a member ends their access at once. Every request checks membership in the database. **[verified]** EMS deactivation also locks the account when it belongs to no other workspace. A workspace admin never controls an account that also belongs to another customer's workspace. **[verified]** |
| Access reviews | Admins see every member, role, two-step status and last sign-in on the workspace security page. **[verified]** |

## 3. Data security

| Question | Answer |
|---|---|
| Encryption in transit | HTTPS only. HSTS `max-age=63072000; includeSubDomains`. The `.dev` domain is HSTS-preloaded in browsers. Database and storage connections from the server use TLS. **[verified]** |
| Encryption at rest | Supabase encrypts databases, backups and storage at rest (AES-256), per Supabase's documentation. Vercel stores no customer records. |
| Customer data segregation | Logical, per workspace, in one database. Row-level security is enabled on every table, and policies check workspace membership, role and two-step sign-in. Storage objects are workspace-prefixed and checked on every request. The hosted suite's bucket has no user access; the server acts only after the database approves. **[verified]**, with 500 automated database checks in the repository. |
| Hosting location / data residency | One Supabase project and one Vercel project. Alderworks gives the Supabase region in writing on request. **[plan]** Regional residency options are not offered. |
| Backups | Daily database backups by Supabase. Seven days of history were observed on 2026-08-23. **[plan]** A restore to a separate project was tested on 2026-08-24, including records, a certificate PDF from storage and the public verification page. Point-in-time recovery is a paid add-on and is not enabled. **[plan]** Uploaded files and the team folder are held in Supabase Storage (durable object storage). Whether storage objects are part of the provider's backups depends on the provider; confirm before relying on it. **[plan]** |
| Data retention | Customer records are kept while the workspace exists. After a trial ends or a subscription is cancelled, data stays readable and exportable, and only new work is blocked. **[verified]** A suspended workspace is kept 30 days, then permanently deleted on the operator's action. The deletion is recorded and not archived. **[verified]** |
| Data export | EMS: CSV and PDF exports of equipment, calibrations, work orders, maintenance and the activity log. Hosted suite: files are stored in their own formats; the workspace activity log exports as CSV. A single "download the whole team folder" export is not built yet; Alderworks exports it on request. |
| Deletion on request | By the operator, per workspace. Deletion is permanent. |
| File upload controls | Hosted suite: only xlsx, html, htm, json, pdf, csv, docx, txt, png, jpg, jpeg, gif and webp; 25 MB per file; a folder quota per plan (2 to 50 GB); saves are version-checked so nobody silently overwrites another person's work. **[verified]** EMS: uploaded certificates and attachments are served only if they are PDFs or images, through 60-second links. **[verified]** |
| Card data | Never touches Alderworks' systems. Payment happens on Stripe's hosted pages. **[verified]** |
| Secrets management | Server keys are environment variables on the hosting platform, never in the repository or the browser bundle. A built bundle was checked for them. **[verified]** |

## 4. Logging and monitoring

| Question | Answer |
|---|---|
| Audit log available to the customer? | Yes. The workspace security page shows and exports as CSV: sign-ins and account events (from Supabase Auth, with IP address where recorded), people and role changes, sign-in setting changes, two-step resets, EMS record activity, and every hosted-suite file save and removal (who, when, file, version). **[verified]** Sign-in history depends on the auth audit log being written to the database. **[plan]** |
| Tamper resistance | Nobody signed in to a workspace, of any role, can update or delete a log entry. Entries written from a signed-in session are stamped with that person and the database time. Calibration approval history and issued certificates cannot be rewritten. **[verified]** The service role (Alderworks server) is not technically prevented from changing rows. |
| Log retention | For the life of the workspace. Auth audit entries follow Supabase's retention. **[plan]** |
| Operator (Alderworks) actions | Lifecycle, billing, support and demo actions are recorded in an operator audit trail that survives a workspace purge. **[verified]** |
| Intrusion detection / SIEM | Platform-level monitoring is provided by Supabase and Vercel. Alderworks runs no SIEM of its own. |

## 5. Application security

| Question | Answer |
|---|---|
| Secure development | TypeScript with strict type checking, linting and unit tests on every change (CI). Database policy tests in the repository. Dependency audit in CI plus automated dependency update pull requests. **[verified]** |
| Known vulnerabilities in dependencies | `pnpm audit --prod` reports none on the branch. **[verified]** |
| OWASP Top 10: injection | Database access goes through the Supabase client and parameterised SQL functions. No string-built SQL from user input. **[verified]** |
| Cross-site scripting | React escaping throughout. An enforced Content Security Policy blocks scripts from other domains, plugins and framing by other sites. **[verified]** |
| CSRF | Not applicable to the API. Requests authenticate with a bearer token the application attaches, never with ambient cookies. Stripe webhooks are HMAC-verified with a 5-minute window. **[verified]** |
| Security headers | CSP (enforced), HSTS, X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy, Cross-Origin-Opener-Policy same-origin. No X-Powered-By. **[verified]** (measured on a production build) |
| Rate limiting | Supabase Auth limits sign-in and sign-up. The application limits starting purchases, public certificate and equipment PDFs, downloads, workspace creation, password setup and invitations per IP or per user, counted in the database so every server instance shares one count. **[verified]** |
| Error handling | Error responses give a plain sentence and a reference code, never stack traces or internal messages. **[verified]** |
| Input validation | Server routes validate types, lengths, UUIDs and file paths before use. **[verified]** |

## 6. Business continuity and incident response

| Question | Answer |
|---|---|
| Uptime SLA | **[no]** No contractual uptime commitment. Availability depends on Vercel and Supabase. |
| Status page | **[no]** Not yet. Affected customers are notified directly. |
| Incident response | Alderworks investigates, contains, and notifies affected customers of what happened, what it affected and what is being done (privacy policy, section 8). Contractual timelines can be agreed in a DPA. |
| Vulnerability disclosure | support@alderworks.dev, published at `/.well-known/security.txt` (RFC 9116) and on the Security page. Reports are acknowledged, and reporters are credited if they wish. **[verified]** |
| Disaster recovery | Restore from the daily Supabase backup to a new project (tested 2026-08-24), then repoint the deployment. Recovery point: up to 24 hours without point-in-time recovery. **[plan]** |

## 7. Offline apps (for comparison)

SpecRun, ShiftHandover, RetainLog, PullPlan, CoverPlan and the Alderworks Quality Suite download are single HTML files. They run in the browser, make no network requests and have no accounts. IT controls them like any document: where they are stored, who can open the folder, and the browser policy. See [hosted-vs-offline.md](hosted-vs-offline.md).
