Security & your data

Your data, handled honestly.

No jargon and no overselling. Here's exactly where your data lives, who can see it, and the principles we build the whole platform by.

Where your data lives

We'll always tell you the real answer — and it changes as the platform grows up.

🖥️ Today Demo

Right now the modules run entirely in your own browser. When you add a lead or an invoice, it's saved on your device — nothing is sent to a server, so there's nothing out there to leak.

  • No account, no cloud copy
  • Clearing your browser clears its data — export a backup first
  • Great for trying it risk-free

🔐 Phase 2 Coming

When you go live for real, we add secure accounts and a private backend so your data syncs across your devices and your team — encrypted in transit, access controlled per user.

  • Your own account and login
  • Role-based access for staff
  • Backups and export whenever you want

The principles we build by

These don't change between phases.

🔑

No secrets in the browser

API keys, passwords and integration secrets never live in pages a visitor can read. They stay server-side, always.

📤

Your data is yours

You can export a full backup of your leads, invoices and records at any time. It's your business — we just hold it safely.

🚪

No lock-in

Leave whenever you like and take your data with you. We'd rather earn the relationship every month.

👁️

Least access

People only see what their role needs. Staff see their shifts; owners see the whole picture.

🧾

Plain-English answers

Ask us where anything lives or who can see it and you'll get a straight answer, not a runaround.

🌱

Only what we need

We collect the minimum to run your tools well — not a pile of data we don't have a use for.

What we do & don't do

✅ We do

  • Keep integration secrets server-side, never in client pages
  • Let you export and delete your data
  • Tell you honestly what stage the platform is at
  • Scope staff access to what their job needs
  • Encrypt your data in transit once you're on an account

🚫 We don't

  • Sell or share your business data with anyone
  • Bury secrets or API keys in the browser
  • Claim certifications we don't have
  • Trap your data to stop you leaving
  • Collect information we have no use for

Straight talk: The Ship is in active development. Formal certifications (things like SOC 2) come with a mature backend, not a demo — we'll say clearly when we have them rather than imply it now. Questions about your specific setup? Ask us.

Questions about your data? Just ask.

Tell us about your business and we'll walk you through exactly how your information would be handled — before you commit to anything.

Find my solution →