SolarWright

Security

This page lists controls that are in the product today. It does not claim SOC 2, ISO, HIPAA, or a third-party audit we have not bought.

Who can see a shop's data

Each login sees its own rows. Database policies use the signed-in user id. A teammate sees the owner's workspace only after the owner invites them. The service-role key used by servers and agents bypasses those policies and is never shipped to the browser.

Payments

Cards go to Stripe. We do not store card numbers. SolarWright is $169/month. Each Wright app has its own Stripe webhook secret so a Restore event cannot mark a Roof shop paid.

Photos

Job photos go in a private bucket. Links are signed. We do not put customer job photos on a public CDN path.

Mail

Outbound customer mail goes through a send gate (unsubscribe, frequency, halt switch). Contact form rows are stored before the confirmation email is sent.

What this is not

Not a pentest report. Not an insurance policy. Not "bank-grade" marketing. If a control is not on this page, do not assume it exists.

Privacy · Terms · Start free