Security
This page lists controls that are in the product today. It does not claim SOC 2, ISO, HIPAA, or a third-party audit we have not bought.
Who can see a shop's data
Each login sees its own rows. Database policies use the signed-in user id. A teammate sees the owner's workspace only after the owner invites them. The service-role key used by servers and agents bypasses those policies and is never shipped to the browser.
Payments
Cards go to Stripe. We do not store card numbers. Each Wright app has its own Stripe webhook secret.
Photos
Job photos go in a private bucket. Links are signed.
What this is not
Not a pentest report. Not an insurance policy. If a control is not on this page, do not assume it exists.