SSABI.COM / HOW WE PROTECT YOUR DATA

How we protect your data

Your customer list, your rates, your job history. Here is where it lives, who can reach it, what happens when someone deletes the wrong thing on a Friday afternoon, and how you get all of it back out.

LAST UPDATED 20 JULY 2026 — WRITTEN FOR THE PEOPLE WHO RUN THE BUSINESS

The short version

Your workspace is walled off

No other company's account can read a single row of yours. The database checks it on every request.

Locked on the way there and while it sits

Scrambled in transit and scrambled on disk, using current standards.

Files are copied every night

Every photo, signed document and attachment gets a spare copy, kept for thirty days after a deletion.

Nothing quietly disappears

Removing a record marks it as entered in error instead of erasing it, and the change is recorded.

People see only their part

Each role opens the sections it needs. A driver does not see your margins.

It is yours to take

Ask and we hand you a full structured export of your workspace.

The details

Your data is separated from every other company's

Ssabi runs many companies on one platform. That only works if the separation is absolute, so it is not something the screens do politely. Every record in the system carries the mark of the workspace it belongs to, and the database refuses to return a row whose mark does not match the person asking. A leak across companies is not a mistake we have to notice and correct. It is a question the database will not answer.

We do not take that on faith either. A suite of 55 self-checking separation tests runs against the live database and has to come back clean before anything ships. Each one signs in as one company and tries to read, change or delete another company's records. If a single one succeeds, the release stops.

Only the people you choose can see it

You set what each role can open, section by section: quotes, invoices, the catalog, the schedule, customer records. Those limits are enforced in the database on every request, not just hidden in the menu, so a person cannot reach past their role by guessing a web address. Your warehouse team can see the gear and the pull sheets without ever seeing what you charged for them.

It is encrypted on the way there and while it sits

Traffic between your browser and Ssabi is encrypted, and the site refuses unencrypted connections outright. The stored data is encrypted at rest on the hosting platform with AES-256. In practice: someone who intercepted the connection, or walked out of a data center with a disk, would have scrambled noise.

Your files are backed up every night

Photos, signed delivery paperwork, insurance certificates and every other upload get a spare copy made automatically each night into a separate private store that nothing in the app can reach. If a file is deleted by accident, the copy stays recoverable for thirty days. Nobody has to remember to run it, and there is no button anyone can forget to press.

The honest boundary: the copy runs nightly, not instantly. A file uploaded and then deleted the same day, before that night's run, may not have a spare copy yet. Everything that survives to the next nightly run is protected. It is a safety net, not a mirror, and we would rather you knew which one it is.

Nothing disappears quietly

Ssabi does not really delete things. Removing a quote or a project marks it as entered in error, with a reason and a name attached, and it drops out of the lists instead of leaving a hole in the record. Underneath, the money-and-commitment records keep an append-only history: who changed what, from what to what, and when. That history cannot be edited or removed from inside the app by anyone, including us. If a number changed, you can find out how.

Getting your data back out

Your data belongs to you and you can have a full structured export of it on request, including while you are still a customer. There is no exit fee and no hostage-taking of your own records. Leaving is easy, which is the only reason staying means anything.

When something goes wrong

We keep a written recovery procedure and we practise it rather than assume it. The file half has been run for real against a large test workspace, not just documented: copies restored, records reconnected, checked line by line. The database half is honest about its state below.

What is not on yet

Listed here so you find out from us now, rather than from your security reviewer later.

Rewinding the database to a moment in time NOT YET

Nightly file copies are live and tested. Rewinding the whole database to, say, ten minutes before a bad afternoon is a hosting plan feature we have not switched on. Until we have, the recovery procedure for it is written but unrehearsed, and we will not describe it as proven.

A second step at sign-in NOT YET

Sign-in today is an email address and a password. A code from your phone as a second step is built into the platform we use and is not yet turned on for your people.

Bringing a security reviewer?

The technical version of this page, written for them, covers the architecture and the same gaps in their language.

Read the security page