Who can see your data

Most business software asks you to trust that the people who built it will behave. We would rather you didn't have to.

Nobody asks this in a form. It comes up in a demo, usually a few minutes after someone starts picturing their real customer list inside the system. So can you see everything in here?

It is a fair question and it deserves a specific answer rather than a page of adjectives.

The short answer

Our support team cannot look at your data unless you let them in

Not a policy. Not a promise about how we hire. They ask, you decide, and the software enforces it.

  1. Support needs to look at something to help you. They ask, and they say why.
  2. You get an email, and a banner appears at the top of your account.
  3. You read the reason and decide. You choose how long: an hour, a working day, a week.
  4. They get in. Only that person, only your account, only for that long.
  5. You can end it early, whenever you want, for any reason.
  6. Everyone in your account can see when we are in there, not just admins.

What we can see without asking

Being upfront about the limits is the part that makes the rest worth believing.

🧾

Always visible to us

The commercial facts of being our customer: your plan, your subscription, your seat count, your storage use and whether your email is being delivered.

🔒

Not without your approval

Your inventory, your customers, your orders, your invoices and your costs. The operational data you actually run the business on.

One exception, and we will tell you about it. If something is badly broken and nobody at your company can respond, a senior engineer can let themselves in to fix it. You get an email the moment it happens, with the reason, and it is permanently marked as emergency access in your records. You can still end it immediately.

We built it this way on purpose. A support team that cannot work during an outage finds another way in, usually a shared password or a direct database connection, and those leave no trace at all. This one leaves a trace every time.

What was already true before any of this

The approval step is new. The rest of it has been how the product works for a while.

  • Nobody wanders in unannounced. Every time our staff open your account they have to say why, in at least a sentence, and it is written down against their name with the time and their IP. It cannot be skipped, because it is enforced on every way in rather than just the obvious button.
  • Access ends by itself. An hour, enforced by the clock. After that they have to ask again.
  • You can see what we changed. If our support team changes something, it shows up in your own change history attributed to the staff member, with "(Support)" beside their name. It is never disguised as one of your own people.
  • Our own staff have limits. Support, Billing and Engineer are three different levels of authority, and new staff accounts start at the lowest. Someone who can help you with a stuck order cannot change your plan or switch your account off.
  • Your people have limits too, if you want them to. You decide who in your business can do what, down to individual locations. Someone at one warehouse does not have to see another warehouse's stock.
  • Keys cannot outgrow the person holding them. An API key can never do more than the person it belongs to. Revoke someone's access and every key they hold narrows with it.
  • Connections have to prove who they are. We reject data from a connected service that cannot prove it came from that service.
  • Mistakes are reversible. Most changes can be undone, and records are not deleted out from under you.

What we do not claim

If a page like this only lists strengths, it is advertising. Here is the other half.

We are not SOC 2 certified. It is a goal, not a fact, and we will say so until an audit has actually happened.

Your data is not end to end encrypted. It is encrypted in transit and at rest, and specific credentials are encrypted at the application layer on top of that. Those are real protections, but end to end means something specific and this is not it.

We do not offer MFA or single sign on yet, and we do not offer EU or UK data residency. We would rather you read that here than discover it in procurement.

And the honest boundary on everything above: this is a promise about what the product will show our support team. Engineers who run the infrastructure can reach the database, the same as at every company that hosts software for you. What we can tell you is that the ordinary path, the one used every day to answer support tickets, does not open without you.

See it from the inside

The access banner, the change history and the permission settings are all in the trial. No card to start.