Trust & Security

Security enforced before the first line of code.

Residents hand you SSNs, driver's licenses, and bank details. A maintenance platform that touches that data earns the full security workup — so FixGrid was built to pass it: query-level tenant isolation, MFA, an append-only audit log, and a security ruleset enforced on every change. Send this page with your questionnaire, then see the product on a live demo or check pricing.

9 event categories · append-only 0 High findings · authenticated ZAP AES-256 at rest · TLS in transit
Audit Log · SYSLOG-1 LIVE Dark
Append-only · database-enforced Records can't be altered or deleted — only added.
Try it — select a line, then Tamper test. The log refuses, and logs the attempt.
The controls procurement asks about

Six layers, each already in production — not a roadmap of someday.

You're signing a portfolio onto a platform that holds resident PII. The diligence questions have real answers: here's what's protecting the data on day one.

Access control MFA, role-based, least privilege. Every authenticated route is gated by an explicit permission. MFA — passkeys and email codes — is enforceable for staff, with trusted devices and recovery codes. Unique account per user; no shared logins. Passkeys / WebAuthnEmail codesPer-module permissions
Tenant isolation Scoped at the query layer. Your company is enforced on every database fetch — never as a check applied after the data comes back. One tenant's records are structurally unreachable from another's. Query-level scopingNo post-fetch filtering
Encryption Encrypted in transit and at rest. TLS enforced site-wide via Cloudflare. AES-256 at rest across managed PostgreSQL and object storage. PII is never written to application logs; secrets are never logged. TLS site-wideAES-256 at rest
Audit log Append-only, across 9 categories. Authentication, MFA, authorization, user lifecycle, admin actions, billing, webhooks, security, and data exports — all written to a log that's database-enforced immutable. Who did what, when, on which record. ImmutableSYSLOG-1
Secure development Enforced before code is written. A standing SEC-1…10 ruleset is checked at write time on every change. SAST and dependency scans run before every push, behind a CI gate. ORM-only queries and global auto-escaping structurally rule out SQL injection and XSS. Bandit + SemgrepCI security gate0 open High
Edge defense Hardened at the perimeter. Cloudflare provides edge TLS and DDoS resilience. Turnstile guards public forms, rate limiting throttles abuse, and a full set of security headers — CSP, HSTS, frame-ancestors — ships on every response. Cloudflare DDoSTurnstileRate limiting
Enforced before written, not audited after

Most teams scan for vulnerabilities after they ship. We gate them before they merge.

Security isn't a quarterly review here — it's a property of the codebase. A standing ruleset blocks insecure patterns at write time, the CI gate refuses to merge un-triaged findings, and a zero open Critical/High bar is held continuously. The result isn't a promise; it's a pipeline.

Write timeSEC-1…10 rulesetInsecure patterns are flagged as code is written, not discovered later enforced
Static analysisBandit + SemgrepSAST runs on every push, behind a CI gate that blocks un-triaged findings CI gate
Dependenciespip-audit + SafetyThird-party CVEs are caught and remediated before they reach production per push
Dynamic testingAuthenticated OWASP ZAPActive scan across 100+ endpoints behind login — zero High findings 0 High
Ship gateZero open Critical / HighFindings are remediated before code ships — the bar is held, not aspired to held
Multi-tenant isolation

Your data is unreachable from anyone else's — by construction, not by policy.

The most expensive failure in shared software is one customer seeing another's data. FixGrid closes that off at the lowest level: every read is scoped to your company in the query itself. There's no "remember to filter" step that someone can forget — the boundary is the query.

  • Every fetch scoped to your tenant — enforced in the database query, not after.
  • No post-fetch checks to bypass; cross-tenant reads simply return nothing.
  • Verified by an authenticated scan across 100+ endpoints — zero High findings.
Tenant Isolation Dark
Request · authenticated as
Riverside PM → fetch service_history
scope = company_id: riverside-pm
Riverside PMcompany_id: riverside-pm Returned · 248 records
Lakeside Groupcompany_id: lakeside-grp Out of scope
Hartwell Residentialcompany_id: hartwell-res Out of scope
The scope is the query. Other tenants' rows are never fetched, so there's nothing to accidentally leak downstream.
Validations & roadmap

What's verified today — and what we're honest about still building.

Self-attested and scan-verified trust is in place now. The paid third-party layer that unlocks enterprise procurement is sequenced deliberately, cheapest and most-required first. We'd rather tell you exactly where the line is than imply a badge we don't hold.

In place todayVerified
  • CSA STAR Level 1 · CAIQ v4.1Listed publicly; the standard security questionnaire is answered and on file.
  • Authenticated OWASP ZAP — 0 HighActive scan across 100+ endpoints behind login, not just the public surface.
  • PCI resolved via StripeCard data never touches our servers; AOC on file. Webhook signatures verified.
  • 10-document policy setInformation Security Policy, DPA template, Incident Response Plan, sub-processor list — shareable on request.
  • Append-only audit log + MFAImmutable event trail across 9 categories; enforceable multi-factor for staff.
Why the candor? Real security teams read pay-for-display trust seals as a negative signal. We'd rather show you a scan report and a policy set you can actually read than claim a certification that isn't operational yet. When it is, it'll be listed here — dated.
Bring the questionnaire

Send us your security review. We'll answer it line by line.

A 30-minute walkthrough on your own portfolio, plus the policy set and scan results your team needs to clear vendor diligence. No hand-waving — the real posture, on the record.

Security contact · [email protected] · Pricing