TowerVue
TowerVue
Sign in →
SOC 2 Type II — Audit window 2026-H2

Security & Trust

TowerVue is built for the yard crews who depend on it and the security teams who audit it. Here is exactly how we protect your data.

SOC 2 Type II

TowerVue is pursuing SOC 2 Type II certification under the Trust Services Criteria for Security, Availability, and Confidentiality. The audit window opened June 22, 2026. Evidence is collected daily, automatically, and recorded in a hash-chained ledger that cannot be retroactively altered.

To request a copy of our report or security documentation, contact security@towervue.app

Core architecture

Isolation

Every TowerVue customer runs on a physically dedicated database. There is no multi-tenant database where a misconfiguration could expose your rows to another customer. Isolation is not a configuration flag — it is structural. An automated probe writes a unique canary record to one customer's database every day and verifies it does not appear in any other. The result is recorded as cryptographically verifiable evidence.

What we control and how

CC6.1Data stays in your lane

Every customer operates on a physically dedicated database. Your data has never shared infrastructure with another customer — proven by an automated daily canary test that verifies isolation at both the storage and routing layers.

CC6.2Access is granted formally

Access to TowerVue systems is provisioned through a documented process. Every grant is logged in our append-only compliance ledger. Quarterly access reviews ensure the list stays current.

CC6.3Access is revoked immediately

When a user is deactivated, all active sessions and refresh tokens are invalidated in the same transaction. There is no window between deactivation and lockout.

CC7.1Vulnerabilities are tracked and remediated

Our dependency vulnerability inventory is ingested automatically from GitHub Dependabot and verified weekly. Remediation SLAs: Critical 7 days, High 30 days, Medium 90 days.

CC7.2Sensitive actions are logged

Authentication failures, administrative actions, and impersonation events are captured in real time and forwarded to the compliance ledger. Nothing is retroactively editable.

CC7.3Incidents are reported within 72 hours

Security incidents are tracked through a structured incident register. Affected customers are notified within 72 hours of discovery. Annual tabletop exercises keep the response process current.

CC8.1Changes go through review

All production code changes flow through GitHub with peer review. Our change-attestation webhook captures every merge to the main branch as a timestamped compliance event.

CC9.2Vendors are reviewed quarterly

Third-party service providers — infrastructure, email, monitoring — are assessed quarterly for security posture. The current vendor inventory is maintained in our compliance record.

A1.2Backups are verified, not just taken

Point-in-time recovery bookmarks are pulled from our database infrastructure weekly and stored as evidence. Quarterly restore drills verify that recovery actually works — not just that the backup job ran.

C1.2Your data is yours to take

Customers can request a full data export at any time. On offboarding, data is exported and then deleted within 30 days. The full process is logged and auditable.

Security questions or report requests

We respond to security inquiries within one business day.

Contact Security