SupportLog in
Maintenov
ResourcesPricing
Book a demo Start free trial

What we actually do about security.

Facilities data includes building access, floor plans and vendor records. Below is exactly what is in place today, and exactly what is not - because a page that only lists strengths tells you nothing.

In place today

Built in, and verifiable.

Tenant isolation

Every record carries an organisation id and every query filters on it. There is no code path that reads a record by id alone. This is tested directly: a signed-in user of one organisation attempting to read or modify another gets nothing back.

Password storage

PBKDF2-SHA256 at 210,000 iterations with a unique salt per user, which is current OWASP guidance. Plain passwords are never stored or logged.

Encryption in transit

HTTPS everywhere, enforced by the platform. Data at rest is encrypted by Cloudflare D1, our database provider.

Session handling

Sessions are random 32-byte tokens in HttpOnly, SameSite cookies. Only a SHA-256 of the token is stored, so a database dump cannot be replayed as a login.

Audit logging

Sign-ins, failed sign-ins, invitations and record changes are written to an audit table with actor, timestamp and IP.

Infrastructure

Runs on Cloudflare Workers and D1. Their platform-level security, DDoS protection and physical data centre controls are inherited, and are considerably better than anything a company our size could build.

Not yet in place

What we cannot claim.

If any of these is a hard requirement for your procurement process, Maintenov is not ready for you yet, and we would rather tell you now than waste your evaluation.

No SOC 2 report

We have not been audited. A SOC 2 Type II takes a year of observation and significant cost, and we will not pretend otherwise.

No contractual uptime SLA

The underlying platform is highly available, but we do not yet offer a contractual availability guarantee with financial remedies.

No SSO or MFA yet

SAML and OIDC single sign-on, and multi-factor authentication, are designed but not built.

No data residency choice

Data location follows Cloudflare defaults. Region pinning is not offered yet.

No penetration test

No third-party penetration test has been commissioned. One is planned before we take on public sector customers.

No VPAT

The product is built with accessibility in mind, but no formal accessibility conformance report exists.

Questions

Straight answers.

On Cloudflare D1, distributed across their network. We do not currently offer a choice of region. If data residency in a specific country is a legal requirement for you, we cannot meet it today.

Yes, and this matters more than any certificate. Ask us at any time and we will provide a complete export of your records. Self-service export from inside the product is being built.

No. Your operational data is not used to train models, is not shared between organisations, and is not sold. The assistant on this website answers from public marketing content only and has no access to any customer data.

We would notify affected customers directly and promptly with what we know, what was accessed, and what we are doing. We have no formal incident response certification, but we have a plan and a very short chain of command.

Maintenov it.

Ask us the hard questions.

If your IT team needs detail this page does not cover, write to us and you will get a direct answer rather than a sales deck.