Skip to content
Trust & legal

Security and your company’s information

How Soffyt controls workspace access, protects private files, and handles connected services—with practical steps for your team.

Access follows your organization and role

Soffyt uses organization membership and permissions to control access to company records and actions. Roles distinguish viewing information, making changes, managing settings, and accessing internal costs. A customer portal provides a separate view of information shared with that customer.

  • Give each team member their own account and the access needed for their work.
  • Review membership and permissions when someone joins, changes responsibilities, or leaves.
  • Check the selected organization before working with records if you belong to more than one company.
Set up company and team access

Location sharing and field records

Live location requires an authorized technician to enable sharing during an active shift and grant device permission. The server checks the user, company, active shift, and sharing session before accepting points. Viewing the feed requires dispatch and location permissions. The live feed holds the latest point rather than a GPS route history; time records and vehicle service history have separate lifecycles.

  • Limit live-location and time access to the people who need it for their work, and review access when roles change.
  • A missing or stale location does not establish whether someone worked. Device settings and connectivity affect updates; review the actual time records and corrections.
Read location and retention details

Sign-in and account protection

Soffyt supports organization policies for multi-factor authentication and additional authentication for sensitive actions. Available controls depend on the configured authentication service. Administrators should review the policies available in their workspace, enable the protections appropriate to their team, and keep account recovery details current.

  • Use a unique password and keep verification codes and recovery information private.
  • Keep access to the email account used for invitations and account recovery secure.
  • Report unexpected sign-in activity or a lost device with workspace access to your administrator and Soffyt support.

Private files and customer sharing

Soffyt’s private file-storage flow uses organization-scoped file paths and temporary download links. Access also depends on the record and sharing permissions involved. Company defaults and supported visibility controls determine which quotes, invoices, appointments, and files customers can see.

  • Review the customer-facing view before sharing a record or document.
  • Treat portal and download links as sensitive. Share them only with the intended recipients.
  • Check a file’s contents as well as its visibility; changing access cannot recall a copy someone has already downloaded.
Review customer portal visibility

File safety checks

Soffyt supports a configured scanning service for uploaded-file threat checks. When required scanning is enabled, the upload flow rejects detected threats and unsuccessful scan results. Files restricted by their security status cannot be downloaded through the protected file flow. Scanning availability and coverage depend on the deployed configuration; this page does not represent every file as scanned.

  • Uploaded content can be sent to the configured scanning provider for analysis.
  • A successful scan does not establish that a document is accurate or suitable to share.
  • If a file is blocked, contact support with the affected record and error message rather than repeatedly uploading it.
Understand file-scanning providers

Connections and payment details

Google and Microsoft present their own authorization screens for connected accounts. Google Drive template access is a separate connection from email. Review the account and requested permissions before authorizing a connection. Soffyt uses authorization credentials from the provider; do not send the team your mailbox password.

  • Disconnecting a connection stops future access through it; messages, attachments, and published documents already stored in Soffyt may remain as company records.
  • Stripe-hosted checkout handles customer card entry. Soffyt uses payment references and transaction information to connect payments with invoices.
  • Keep full card numbers, card security codes, passwords, and access tokens out of ordinary notes, files, and support messages.
Review supported connections

Data protection and security records

Our privacy policy describes encrypted network connections, protected credential storage, private file access, organization-based permissions, and security logging. Security and technical records help investigate errors, misuse, and incidents. Access to customer information and its permitted uses are governed by the applicable policies and agreements.

Read how Soffyt handles information

Retention, deletion, and recovery requirements

Archiving a record, disconnecting an account, cancelling a subscription, and requesting deletion are separate actions. Coordinate with your administrator and Soffyt before closing a workspace so the records your company needs can be identified and return or deletion instructions agreed.

  • The privacy policy explains retention criteria and limited exceptions. Residual backup copies expire under the applicable backup lifecycle; deletion instructions must be reapplied if those copies are restored.
  • If your business requires a particular backup frequency, recovery time, recovery point, or retention period, request the current service details and establish any required commitment in writing.
Discuss retention and data return

Security reviews and agreements

For a vendor review, send the requirements relevant to your organization and the features you intend to use. Request current evidence for controls, processing locations, recovery arrangements, or independent assessments that matter to your decision. This page is a service overview; it does not establish certification, an uptime guarantee, or a particular data-residency commitment.

  • The service agreement and any accepted data processing agreement govern contractual security, incident notification, and assistance obligations.
  • Provider names alone do not establish where information is processed. Review the applicable processing schedule and any agreed location restrictions.
Review the data processing agreement

Report a security concern

Email support@soffyt.com with a brief description, the affected feature or page, and the approximate time and time zone. Include a way to contact you and, if relevant, the steps that revealed the issue. Begin with a description that excludes passwords, access tokens, full payment details, and unnecessary customer information. The team can coordinate how to share additional evidence.

  • For privacy requests or questions about personal information, contact privacy@soffyt.com.
  • If you encounter information you should not be able to access, stop accessing it and report the issue. Do not download additional records or test against other customers’ workspaces.
  • Keep your organization’s account and security contacts current so the right person can receive follow-up information.
Report a security concern
People behind the platform

Let’s get you to the right place.

Questions about Soffyt? We’re here to help.

Contact support