Security & privacy
You're handing us insurance documents. Here's how they're handled.
Written plainly, and limited to what's actually true today — no badge wall, no certifications we haven't earned.
Access and accounts
- Passwordless sign-in by emailed magic link — there's no password to breach or reuse
- Sessions are server-side; links expire and are single-use
- Every account's data is scoped to that account at the database level, and we run automated tests specifically designed to catch a query that isn't
- Read-only team members are enforced on the server, not just hidden in the interface
Your subcontractors' upload links
The links we email subs are the credential, so they're treated like one: stored hashed, expiring after 30 days, and limited in how many times they can be used. A sub never creates an account and never sees anyone else's data.
API access
API tokens are stored hashed — we can show you the prefix, never the token. You issue and revoke them yourself, and revocation is immediate. Requests are rate limited.
Your data
- Export everything to CSV in one click, without asking us — including for 30 days after you cancel
- We don't sell data, and we don't train external AI models on your documents
- Hosted in the United States on managed infrastructure with encrypted connections and automated backups
Reporting a problem
Found something? Email justin@jackedtrade.com. We'll respond, and we won't threaten anyone who reports a vulnerability in good faith.
Start your 14-day free trial
Add your first subcontractors in minutes — SubTrack reads the certs, flags the gaps, and chases renewals for you.
14 days free, then $49/user·mo. Card required — cancel anytime before it ends and you're not charged.