Security
Last updated October 2, 2026
Install Direct handles homeowners’ contact details, service addresses, home equipment information, and payment confirmations, plus the job and payout records of the contractors in our network. Protecting that data is core to the product, not an afterthought. This page describes our security program at a high level; our controls are governed by internal policies and reviewed against the SOC 2 Trust Services Criteria.
Encryption everywhere
All traffic to Install Direct is served over HTTPS/TLS, with HTTP Strict Transport Security enforced across the domain and its subdomains. Data at rest — our database, backups, and uploaded files such as installation photos — is encrypted by our infrastructure providers. Uploaded files live in private storage and are only reachable through short-lived signed URLs issued after an ownership check.
Least-privilege access
Every table in our database enforces row-level security, so the database itself refuses to return a record to anyone not entitled to it — the application layer decides what to show, but the database is the real boundary. Staff access is role-based (from sales up to super admin), and each area of the back office re-checks the caller’s role rather than trusting the page that linked to it. Privileged credentials that bypass these rules are used only for a handful of system tasks with no human in the loop.
Multi-factor authentication
Staff and contractor accounts can enrol a time-based authenticator app, and once enrolled the second factor is required to reach any sensitive area — it cannot be skipped by navigating directly. Back-office sessions also time out automatically after a period of inactivity.
Monitoring and audit
Sensitive actions are written to an append-only audit log that records who did what and when, stamped by the database rather than the application. We rate-limit sensitive endpoints to blunt abuse and credential-stuffing, apply a strict Content Security Policy and related hardening headers, run application error monitoring, and expose a health endpoint for uptime checks.
Compliance and availability
We are working toward a SOC 2 Type II examination. Our written security policies, access reviews, backup restore tests, and change-management controls are being operated and evidenced against the Trust Services Criteria today; we will publish the report’s availability here once the audit is complete. Live availability of the website, payments, text messages, and email — plus a history of any incidents — is published on our system status page.
Privacy by design
We collect only what we need to price and fulfill an order, and we do not sell personal information. Card details are handled by our payment processor; we never store full card numbers. Homeowners can access, export, or delete their data through our privacy request page. For more on what we collect and why, see our Privacy Policy.
Responsible disclosure
If you believe you’ve found a security vulnerability, we want to hear from you. Email support@installdirect.pro with the details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure, and avoid accessing or modifying data that isn’t yours while testing. We do not pursue legal action against researchers who act in good faith under this policy. Please put “Security” in the subject line; we acknowledge reports within three business days. Out of scope: denial-of-service or load testing, social engineering of staff or customers, physical attacks, and automated scanner output without a demonstrated impact. Our machine-readable disclosure details are published at /.well-known/security.txt.