Security

How NovakOS protects your company's information

Your customer list, pricing, job records and payroll information are the business. This page explains, in plain language, how NovakOS is built to keep them separated, controlled and recoverable.

Company data isolation

Every record in NovakOS — customers, jobs, quotes, invoices, photos, documents, time records — belongs to exactly one company. Access rules are enforced in the database itself, not only in the app, so a user signed in to one company cannot read or change another company's records.

Role-based access

Within your company you decide who sees what. Owners, dispatchers, office staff, accounting and technicians each get access appropriate to their role, and sensitive areas such as payroll, pay rates and billing are restricted rather than open to everyone with a login.

Secure connections

All traffic between your browser or device and NovakOS runs over encrypted HTTPS connections. Passwords are never stored in readable form, and sessions can be signed out from the account.

Payments

Customer payment processing is powered by Stripe. Card details are entered into Stripe's payment components and handled by Stripe — NovakOS does not store raw card numbers. NovakOS records the outcome of the payment against the invoice so your team sees what was paid, when and how.

History and audit trails

Important business records keep their history. Sent quotes are preserved as immutable versions with revisions tracked separately, technician assignment changes are retained, and payment and administrative actions keep an audit record where supported.

Backup and recovery

Company data is backed up, and NovakOS includes tooling for backup and restore along with account recovery for signed-up owners. If a company chooses to leave, deletion is handled deliberately and verified rather than left half-done.

Mobile and offline data

The technician app keeps a working set of job information on the device so it stays usable without signal. That data is scoped to the signed-in user's company and is cleared from the device when the user signs out.

No software can promise it will never face a security incident, and we won't claim otherwise. What we can describe is how the system is built, what it does with your data, and who can reach it. If something changes materially, we'll say so.

Questions about security?

Send us the specifics and we'll answer directly. Our published security and compliance policy is also available.