CommandoS
HomeFAQsContact
Book Demo

Security

Security and data protection

CommandOS is designed to provide operational intelligence while protecting your company’s systems, data, and user access.

Contact us about security

Security overview

Security is considered throughout the way CommandOS connects to data, processes operational questions, and provides information to approved users.

Data protection

Security is considered throughout the way CommandOS connects to data, processes operational questions, and presents information.

Secure access

Platform access is limited to authenticated and approved users based on the permissions configured for their role.

Controlled integrations

CommandOS requests only the system access required for the agreed use cases and uses read-only access where possible.

Customer data ownership

Customers retain ownership of the business data they make available to CommandOS.


01

Data encryption

Data transmitted between supported systems and CommandOS should be protected using HTTPS and industry-standard TLS.

Encryption in transit using HTTPS and TLS

Encryption at rest where supported by the confirmed deployment architecture

Secure handling of integration credentials

Credentials are not displayed unnecessarily to platform users

Confirm your production storage architecture before publishing a definitive encryption-at-rest claim.

02

Authentication and access control

Access is limited to approved users. Permissions may be configured according to the controls supported by the deployed version of CommandOS.

Authenticated user accounts

Role-based permissions

Branch or department access restrictions

Least-privilege access

Session management

03

Data access and integrations

CommandOS requests only the access required for the agreed use cases. Integrations are configured as read-only where possible.

Read-only access by default where supported

Minimum required system permissions

Controlled storage of integration credentials

No source-system write-back unless explicitly approved

Integration access can be removed when a connection is no longer required

04

Customer data ownership

Customers retain ownership of their business data. CommandOS processes customer data only to provide the agreed service.

Customer ownership remains unchanged

Customer data is not sold

Customer data is not used for unrelated advertising

Data use is limited to agreed product and support purposes

05

AI and model usage

Customer data is processed only as required to provide the configured CommandOS functionality.

Data minimization for model requests

Sensitive information should be excluded where it is not required

Third-party model handling depends on the agreed architecture and provider terms

AI-generated responses may require human review

Model output should not be treated as infallible

Do not state that customer data is excluded from model training until this is technically and contractually confirmed for every provider you use.

06

Data retention and deletion

Data retention is determined by the implementation and applicable service agreement.

Operational-data retention periods

Application and access-log retention

Deletion following account termination

Customer-requested deletion

Backup deletion subject to backup cycles and legal obligations

07

Infrastructure and monitoring

CommandOS uses managed infrastructure with controlled production access. Exact infrastructure details should reflect the systems currently deployed.

Separated development and production environments

Application and access logging

Service monitoring

Backup procedures

Dependency and vulnerability updates

Restricted production administration

Add named hosting and infrastructure providers only after confirming the exact production stack.

08

Internal access

Internal access to customer environments is limited to authorized personnel who require access for implementation, maintenance, or support.

Need-to-know access

Restricted administrative access

Access logging where supported

Confidentiality obligations

Access removed when no longer required

09

Incident response

Suspected security incidents are investigated, contained, and remediated according to the applicable response process.

Incident investigation

Containment and access restriction

Impact assessment

Customer notification according to legal and contractual requirements

Remediation and follow-up review

10

Shared security responsibilities

CommandOS is responsible for securing the platform and agreed integrations. Customers retain responsibility for the security of their own environments.

Customer user administration

Source-system permissions

Endpoint and device security

Accuracy of connected business data

Prompt removal of access for former employees

Compliance status

CommandOS is building its security program to support the requirements of growing home service organizations.

Current status

Formal certifications and compliance documentation will be listed here as they become available. This page does not claim SOC 2, ISO 27001, HIPAA, GDPR, or any other formal certification.

Security FAQ

Answers to common questions about data access, integrations, AI usage, hosting, and customer responsibilities.

Your company retains ownership of the business data made available to CommandOS. CommandOS processes that data only to provide the agreed service.

Data transmitted to and from CommandOS should use HTTPS and industry-standard TLS. Encryption at rest depends on the confirmed production deployment architecture.

Integrations are configured as read-only where the connected system supports it. CommandOS does not modify source-system data unless a separate write-back capability is explicitly reviewed and approved.

Data handling depends on the configured architecture and the terms of any model providers involved. The exact model-training policy should be confirmed in your service agreement.

Access restrictions may be configured according to the role, branch, department, or executive responsibility controls supported by your CommandOS implementation.

Deletion and retention following termination are governed by the service agreement, backup cycles, legal obligations, and any agreed transition period.

Hosting details depend on the production architecture used for your implementation. Approved customer stakeholders may request relevant infrastructure details during a security review.

Yes. Architecture, integration access, data flows, and security responsibilities can be reviewed with approved customer stakeholders during implementation or security assessment.

Have a security or architecture question?

Contact our team at security@commandos.ai.

Email security