Pilotis — Build smart. Train safe. Lead better.
Trust & security

Your compliance records deserve better than a shared drive.

Pilotis holds training records, signatures, and worker information. Here is exactly how we protect it, who can see it, and what happens if you leave.

Data encryption

  • All traffic between your browser and Pilotis is encrypted with TLS (HTTPS). We do not serve the app over plain HTTP.
  • Data stored in our managed database and file storage is encrypted at rest by the hosting platform.
  • Uploaded training media, signatures, and documents live in private storage buckets. Files are served only through short-lived signed links generated for an authorized session.
  • Passwords are never stored in readable form — authentication is handled by our managed identity provider using salted, hashed credentials.

Backups & availability

  • The production database is backed up automatically by the managed platform on a continuous basis.
  • Point-in-time recovery is available so records can be restored to a specific moment, not just the last nightly copy.
  • Application code and configuration are versioned, so a bad deploy can be rolled back quickly.
  • We monitor uptime and error rates and treat availability problems as incidents (see below).

Permissions & access control

  • Every account has a role: company owner, safety manager, project manager, supervisor, trainer or evaluator, worker, or read-only external auditor.
  • Access is enforced at the database level with row-level security — not just hidden in the interface. A worker cannot query another company's records even with a crafted request.
  • Workers see their own training, certifications, and passport. Managers see only their own company's crews and job sites.
  • External auditors can be granted read-only access scoped to what they need to review, with no ability to edit records.
  • Anonymous hazard reports are stored without reporter identity; managers see the report and its tracking code, not the person.

Data ownership

  • Your data is yours. Pilotis stores and processes it on your behalf — we do not sell it, rent it, or share it with advertisers.
  • We do not use your workforce records to train third-party AI models.
  • You can export your workers, job sites, certifications, evaluations, and toolbox-talk records to CSV at any time, without asking us.
  • If you leave, you keep the exports. Worker Skill Passports remain verifiable records of training that was actually completed.

Account deletion

  • Any user can request deletion of their account and personal data by writing to our support address from the account's email.
  • Company owners can remove workers and job sites directly from the dashboard; removed records leave active views immediately.
  • On a verified deletion request we remove personal data from production systems within 30 days.
  • Limited records may be retained where a legal or contractual obligation requires it (for example, safety training documentation an employer must keep). We will tell you what is retained and why.
  • Residual copies in encrypted backups age out on the normal backup rotation.

Incident response

  • We log application errors and authentication events and review anomalies.
  • If we confirm a security incident affecting your data, we contain it first, then notify affected account owners without undue delay with what we know and what we are doing.
  • Each incident gets a written post-mortem with root cause and the concrete fix, shared with affected customers on request.
  • Found a vulnerability? Email us at the address below with the details and steps to reproduce. We will acknowledge responsibly disclosed reports and will not pursue researchers who act in good faith.

Security questions before you buy?

We are happy to walk your IT or safety team through how permissions and data handling work. This page describes our current practices and is updated as they change — it is not a certification claim.