Section 01
Independent attestation
SOC 2 Type II attestation completed October 2025; scope: Security and Confidentiality criteria.
Section 02
Role-based access
Every user belongs to an organization and is assigned a role. Roles control which data and actions are visible. Sensitive financial data is never shown to roles that don't need it.
- Super-Admin (group level)
- Manager (unit level)
- Viewer (read-only)
Section 03
Encryption
AES-256 at rest; TLS 1.3 in transit.
Section 04
Authentication
SSO support via Okta; MFA mandatory for Admin accounts.
Section 05
Data retention
Transactional logs retained 24 months; PII retained for duration of contract plus 90 days.
Section 06
Model policy
Customer data is utilized for localized trend analysis only. No cross-tenant data leakage for training purposes without explicit opt-in.
Section 07
No automatic actions
Automatic actions: none. Human approval: all pricing adjustments, labor cuts, and inventory orders must be executed in the source system by a human operator.
Section 08
Reporting a security issue
If you believe you've found a vulnerability, email [email protected] with the subject "Security". We respond to reports promptly and will coordinate disclosure with you.
Questions
Email [email protected] and we'll route your request to the right team at Before Service Solutions, Inc..
Before Service Solutions, Inc.594 Columbia Rd Ste 210, Boston, MA 02125, United States+1 617 821 5031