Security
Security and data protection
CommandOS is designed to provide operational intelligence while protecting your company’s systems, data, and user access.
Contact us about securitySecurity overview
Security is considered throughout the way CommandOS connects to data, processes operational questions, and provides information to approved users.
Data protection
Security is considered throughout the way CommandOS connects to data, processes operational questions, and presents information.
Secure access
Platform access is limited to authenticated and approved users based on the permissions configured for their role.
Controlled integrations
CommandOS requests only the system access required for the agreed use cases and uses read-only access where possible.
Customer data ownership
Customers retain ownership of the business data they make available to CommandOS.
01
Data encryption
Data transmitted between supported systems and CommandOS should be protected using HTTPS and industry-standard TLS.
Encryption in transit using HTTPS and TLS
Encryption at rest where supported by the confirmed deployment architecture
Secure handling of integration credentials
Credentials are not displayed unnecessarily to platform users
Confirm your production storage architecture before publishing a definitive encryption-at-rest claim.
02
Authentication and access control
Access is limited to approved users. Permissions may be configured according to the controls supported by the deployed version of CommandOS.
Authenticated user accounts
Role-based permissions
Branch or department access restrictions
Least-privilege access
Session management
03
Data access and integrations
CommandOS requests only the access required for the agreed use cases. Integrations are configured as read-only where possible.
Read-only access by default where supported
Minimum required system permissions
Controlled storage of integration credentials
No source-system write-back unless explicitly approved
Integration access can be removed when a connection is no longer required
04
Customer data ownership
Customers retain ownership of their business data. CommandOS processes customer data only to provide the agreed service.
Customer ownership remains unchanged
Customer data is not sold
Customer data is not used for unrelated advertising
Data use is limited to agreed product and support purposes
05
AI and model usage
Customer data is processed only as required to provide the configured CommandOS functionality.
Data minimization for model requests
Sensitive information should be excluded where it is not required
Third-party model handling depends on the agreed architecture and provider terms
AI-generated responses may require human review
Model output should not be treated as infallible
Do not state that customer data is excluded from model training until this is technically and contractually confirmed for every provider you use.
06
Data retention and deletion
Data retention is determined by the implementation and applicable service agreement.
Operational-data retention periods
Application and access-log retention
Deletion following account termination
Customer-requested deletion
Backup deletion subject to backup cycles and legal obligations
07
Infrastructure and monitoring
CommandOS uses managed infrastructure with controlled production access. Exact infrastructure details should reflect the systems currently deployed.
Separated development and production environments
Application and access logging
Service monitoring
Backup procedures
Dependency and vulnerability updates
Restricted production administration
Add named hosting and infrastructure providers only after confirming the exact production stack.
08
Internal access
Internal access to customer environments is limited to authorized personnel who require access for implementation, maintenance, or support.
Need-to-know access
Restricted administrative access
Access logging where supported
Confidentiality obligations
Access removed when no longer required
09
Incident response
Suspected security incidents are investigated, contained, and remediated according to the applicable response process.
Incident investigation
Containment and access restriction
Impact assessment
Customer notification according to legal and contractual requirements
Remediation and follow-up review
10
Shared security responsibilities
CommandOS is responsible for securing the platform and agreed integrations. Customers retain responsibility for the security of their own environments.
Customer user administration
Source-system permissions
Endpoint and device security
Accuracy of connected business data
Prompt removal of access for former employees
Compliance status
CommandOS is building its security program to support the requirements of growing home service organizations.
Current status
Formal certifications and compliance documentation will be listed here as they become available. This page does not claim SOC 2, ISO 27001, HIPAA, GDPR, or any other formal certification.
Security FAQ
Answers to common questions about data access, integrations, AI usage, hosting, and customer responsibilities.
Data transmitted to and from CommandOS should use HTTPS and industry-standard TLS. Encryption at rest depends on the confirmed production deployment architecture.
Integrations are configured as read-only where the connected system supports it. CommandOS does not modify source-system data unless a separate write-back capability is explicitly reviewed and approved.
Data handling depends on the configured architecture and the terms of any model providers involved. The exact model-training policy should be confirmed in your service agreement.
Access restrictions may be configured according to the role, branch, department, or executive responsibility controls supported by your CommandOS implementation.
Deletion and retention following termination are governed by the service agreement, backup cycles, legal obligations, and any agreed transition period.
Hosting details depend on the production architecture used for your implementation. Approved customer stakeholders may request relevant infrastructure details during a security review.
Yes. Architecture, integration access, data flows, and security responsibilities can be reviewed with approved customer stakeholders during implementation or security assessment.
Have a security or architecture question?
Contact our team at security@commandos.ai.