SaySoTermsPrivacySecurity

Security at SaySo

How Get Sayso LLC protects your company’s data, your customers’ information and your money. Plain words on purpose. Effective September 28, 2026.

Where your data lives

One place, encrypted. SaySo runs on Cloudflare — the application, the database and the files. Everything is encrypted in transit (TLS, with HSTS) and at rest by Cloudflare. There are no servers of our own to patch.

Your company is walled off. Every record carries your company’s id and every query is bound to it. Another SaySo customer cannot read, write or even see that your records exist. We test this on every audit with two companies attacking each other; the latest run (September 28, 2026) refused all 64 cross-company attempts.

Backups you can count on. The database keeps a minute-by-minute history for 30 days (point-in-time restore), and every version of the application ever deployed is kept and can be restored with one click.

Your money

Stripe holds the cards and bank accounts, not SaySo. Homeowners pay on Stripe’s own secure page; Tap to Pay uses Stripe Terminal. SaySo stores the amount, the date and a label like “Visa ···4242” — never a card or account number. That keeps SaySo in the lightest PCI DSS category (SAQ A).

Every dollar is recorded once. Payments, refunds, tips, card fees and chargebacks each land in your books exactly once, whether they happen on your dashboard, on the homeowner’s page or inside Stripe; the books were re-verified line by line in our September 2026 audit.

Who can see what

Three levels of access. Owner, office and field. A field crew member sees only the stops they are on — never your prices, your money or another customer. Reps see their own jobs. Only the owner can refund, pay a bill, change prices, export data or add API keys.

Access ends the moment you turn it off. Every request re-checks the person’s row, so a deactivated seat is out on their very next tap — no lingering sessions.

Two-factor sign-in. Owners can turn on an authenticator app (TOTP) on the Account page; sign-ins are rate-limited and compared in constant time. Homeowners reach their page through a private link that is theirs alone.

Support access is logged. When SaySo support opens your dashboard to help, the session is recorded and expires by itself. We never use your customer data to compete with you, never sell it, never share it with another customer.

How we build and ship

One change per release. Every release is one numbered change with its own written record, an automated test that drives the real product in a browser (desktop and phone, light and dark), and a gate of about 1,000 checks that must pass before it goes live. Every release can be rolled back in one click.

We audit ourselves. Independent review passes read the code, attack the live product as a stranger, re-run every past test and look at every screen. Findings become fixes the same day, each one recorded. Four such audits ran between September 16 and September 28, 2026.

No secrets in code. API keys live in an encrypted vault, never in the source, and the release gate refuses a build that hard-codes one.

The companies that help us run SaySo

Cloudflare (hosting, database, files) · Stripe (payments) · Twilio (texts and calls) · ElevenLabs (the AI receptionist’s voice) · Anthropic (the AI that writes and reads; your data is not used to train its models) · Resend (email) · Google (maps, calendar, Business Profile) · Intuit and Xero (accounting, when you connect them) · EagleView (roof reports, when you use them). Each one is bound to use your data only to provide its service to us. The full list, with what each receives, is in the Privacy Policy and in our compliance kit.

Your data is yours

Export any time. Customers, jobs, estimates, payments, visits, leads, reviews, team, timeline and the audit log download as CSV or JSON from your dashboard. Every export is logged.

Delete on request. When you close your account, ask for an export first, then ask us to delete what we hold. We remove your company’s records within 30 days of the request once open payments and legal holds clear; the 30-day backup history then ages out on its own.

Text-message consent is kept, never shared. Opt-ins and STOP requests are recorded and honored automatically; mobile numbers are never shared for marketing. Details: text messages.

Found a security problem?

Tell us at support@getsayso.com with “security” in the subject. We read every report, we will not take action against good-faith research, and we will tell you what we did about it.

What we do not have yet — in plain words

SaySo does not yet hold a SOC 2 report or an outside penetration test; we are building toward both, and our written policies, data map, vendor list and risk register are available to customers under NDA today. We would rather tell you exactly where we stand than hand you a badge.