How URBLD protects your business data
Your leads, jobs, contracts and payments are the business. This page explains exactly what protects them, who else touches them, and where we stand on formal certification — written plainly, without the badges everyone else uses.
This page is maintained by URBLD to answer common security and privacy questions about the URBLD platform. It describes our own practices; it is not an independent audit or certification.
Our compliance status, honestly
URBLD is not SOC 2 certified. We have mapped our controls to the SOC 2 Trust Services Criteria for Security, Availability and Confidentiality, written the supporting policies, and we operate and measure those controls internally. A formal audit is planned, not completed. When it is, this page will say so and name the auditor and the report period.
Our infrastructure providers hold their own SOC 2 and ISO 27001 attestations. Their certifications cover their platform, not ours — we do not present them as URBLD certifications.
What is in place today
Tenant isolation
Every record in URBLD carries an organization identifier, and database-level row security policies scope reads and writes to that organization. Your leads, jobs and financials are not visible to another contractor's workspace.
Role-based access
Owners, admins, office staff, technicians and viewers each have a defined scope. Roles are stored separately from user profiles so that a profile edit can never grant elevated permissions.
Multi-factor authentication
MFA is available on every account and is required for accounts holding privileged roles. Sensitive operations can require re-authentication.
Encryption
All traffic is encrypted in transit with modern TLS. Data at rest — including database, backups and uploaded documents — is encrypted by our infrastructure provider. Integration credentials are stored in an encrypted secret store, never in application code.
Server-side authorization
Privileged operations run on the server, where the acting user is resolved from a validated session token. The application never trusts an identity supplied by the browser.
Audit logging
Important and destructive actions are written to an audit trail with the acting person, the affected record and a timestamp. Secrets and signing tokens are redacted before anything is stored.
Deletion that does not destroy
Deleting a lead or job in URBLD marks it inactive rather than erasing it. Permanent removal happens only on account termination or a verified erasure request.
Backups and recovery
The production database is backed up continuously by our infrastructure provider with point-in-time recovery. Our recovery objectives are a 4-hour recovery time and a 24-hour recovery point for critical functions.
Shared responsibility
Our infrastructure providers
Physical security, host and network hardening, encryption at rest, managed database backups, and their own third-party attestations.
URBLD
Application security, tenant isolation, access control, audit logging, secure development and change management, vendor review, and incident response.
You
Who you invite, the roles you give them, enrolling MFA, removing people who leave, and what data your team chooses to store in the platform.
Subprocessors
URBLD uses a small set of third parties to deliver the product. Each one is inventoried with the data it touches and reviewed at least annually. The current named list is available on request with our data processing agreement.
Your data, your rights
You own the data you put into URBLD. We process it to operate the service for you and we do not sell it. Account owners can export their data at any time. We honour access, correction and erasure requests within 30 days, in line with GDPR and CCPA data rights. Operational records are retained for the life of the account plus 30 days; audit logs are retained for at least 12 months.
See our Privacy Policy and Terms of Service for the full legal detail, and our Security overview for a shorter summary.
Frequently asked questions
Is URBLD SOC 2 certified?
No. URBLD is not SOC 2 certified today, and we will not claim otherwise. We have mapped our controls to the SOC 2 Trust Services Criteria for Security, Availability and Confidentiality, authored the supporting policy set, and are operating those controls to build the evidence an audit requires. This page will be updated when that status changes.
Where is my data stored?
In managed cloud infrastructure in the United States, operated by our infrastructure provider. Database, backups and uploaded documents are encrypted at rest.
Can another contractor see my customers?
No. Data access is scoped to your organization at the database level, not just in the interface, so a query that is not scoped to your organization returns nothing.
Can I export or delete my data?
Yes. Account owners can export their data from the platform. Erasure requests are handled within 30 days; data may persist in encrypted backups until those backups age out of the provider's retention window.
How do I report a security issue?
Email security@urbld.com. We acknowledge critical reports within 24 hours. We do not pursue legal action against researchers who report in good faith and avoid accessing other customers' data.
Do you have a data processing agreement?
Yes. Request one at security@urbld.com and we will provide our current DPA along with the subprocessor list.
Security contact
For vulnerability reports, security questionnaires, or a data processing agreement, write to us directly. Critical reports are acknowledged within 24 hours.
security@urbld.com