We treat your data like it's our own.
ServicesGrid OS runs the operational nervous system of your business — bookings, payments, members, staff. We've built the platform on the assumption that any of that information could matter to your customers, your finances, or your survival. Here's how we protect it.
Security controls built into daily operations.
These are the application controls currently represented in the product. Infrastructure commitments and customer-specific requirements are confirmed during rollout review.
Encryption at rest and in transit
Application traffic uses encrypted HTTPS transport. Infrastructure-level storage encryption and backup controls follow the selected managed hosting environment. Payment credentials are handled by supported payment providers rather than stored as raw card details by ServicesGrid OS.
Workspace isolation
Authenticated APIs apply workspace and service scopes, with authorization and tenant-scope checks included in automated test coverage. Privileged support access is handled separately through logged, time-bound sessions.
API keys hashed, never stored raw
Developer API keys (sk_live_…) are hashed with SHA-256 before storage. The raw key is shown once at creation and never recoverable — even by us. Each key carries scopes you choose; revocation is instant and audited.
Managed backup controls
Database backup, retention, and recovery controls follow the active production hosting configuration. Specific recovery objectives, residency requirements, and dedicated deployments are confirmed during Enterprise rollout review.
Logged staff access — including ours
Platform support access uses logged, time-bound support sessions with actor and workspace context. Access is permission-controlled and designed to leave an audit trail for operational review.
Data control workflows
The platform includes account data export and deletion workflows. Contractual privacy, residency, retention, and sub-processor requirements should be reviewed for the customer’s rollout and jurisdiction.
What we're working on next.
SOC 2 Type II
We're in the early stages of a SOC 2 Type II programme. We'll publish the final report on this page once we complete the observation period.
Single Sign-On (SSO)
SAML and OAuth-based SSO for Enterprise tenants — ETA published in the changelog as we get closer. Email-based MFA controls are available today; their availability and enforcement settings are verified as part of each production rollout.
Bring your own region
Enterprise customers with data residency requirements (EU only, US only) can request a dedicated regional deployment. We'll quote setup time at the contract stage.
Found a security issue? Tell us.
We take security reports seriously and respond within one business day. Please email security@servicesgridos.com with reproduction steps. We do not pursue good-faith research — please give us reasonable time to fix before disclosing publicly.
Built with security as a default, not a feature.
14-day free trial. No card required. Workspace data is access-scoped, protected in transit, and available for authorized export.