syteOn
Login Book a Walkthrough
Company / Security & Trust
Security & trust

Your company runs on the data inside syteOn. We treat it that way.

syteOn is designed to keep company data separated, access controlled, activity traceable, and integrations intentional — while giving your team the information they actually need to do their work.

Where we are today — plainly
{{ s.what }} {{ s.state }}
In review means the control is built into the design and pending a formal verification pass — not that it's marketing. We'd rather show you that distinction than round everything up to "live".
The foundation

Security should be part of the operating model — not a feature added later.

{{ p.num }}
{{ p.title }}

{{ p.body }}

Data separation

Your company's workspace belongs to your company.

syteOn is built as a multi-tenant operating platform. Company records are scoped to the tenant they belong to — your customers, projects, people, and financials sit inside your environment, not a shared pool.

{{ t.tag }} {{ t.state }}
{{ t.name }}
{{ r }}
Records are scoped to their tenant by design — a user authenticated to one company is not able to address another company's records. Design — under review
Permissions

The crew doesn't need the owner's financials.

One project — Keller Addition #2081 — seen through six different roles. Same underlying record, different permissions.

Signed in as
{{ roleName }}
Keller Addition · project #2081
Can see
{{ c }}
Cannot see
{{ c }}
{{ roleNote }}
Access follows the role
{{ a.label }}

A user's access is determined by their tenant, their role, the work assigned to them, and — for customers and subcontractors — the specific relationship that grants it.

Account access
{{ a.what }} {{ a.state }}
Items marked planned are not available today. We list them so you can plan, not so the page looks longer.
Accountability & AI

AI is designed to work inside your permissions — not around them.

And important actions don't disappear without a record. AI activity is attributed as AI, never as one of your people.

Activity — project #2081 Who · what · when
{{ a.at }}
{{ a.who }} AI
{{ a.what }}
Entries are designed to carry who acted, what changed, when, and which record — with AI actions labelled as such. Ask us about current coverage and retention.
What each assistant can reach
{{ a.who }}
{{ s }}
The model is that an assistant inherits the permissions of the person using it — so a field user shouldn't reach owner-level financials by asking an assistant instead of opening a screen. If this is a control your company depends on, ask us to walk through the enforcement before you rely on it.
AI prepares · your team decides
{{ s.label }}
AI does not commit on its own
{{ n }}
Boundaries that matter most

Your customer sees their project — not your company.

Financial visibility doesn't mean financial access for everyone, and employee information stays with the people who need it.

{{ b.tag }}
{{ b.title }}
Can see
{{ c }}
Cannot see
{{ c }}
Infrastructure, connections & payments

A connection should only have the access it needs.

How the platform is layered
{{ l.label }}

syteOn runs on AWS infrastructure. That's a statement about where we host — not a certification of syteOn, and not a security guarantee from AWS.

Connected systems
{{ i }}
{{ c.label }}
Each connection is authorized for the workflow it serves and revocable where the provider supports it. Third-party services keep their own security and privacy practices — we don't control them and won't claim to.
Payments
Payments are designed to route card and bank details through the connected provider's infrastructure rather than syteOn's own storage.
{{ p.label }}
syteOn records the invoice, the amount, and the payment status against the job. The processor handles the instrument, and its security is governed by its own infrastructure and terms.
Your data

A software decision shouldn't become a hostage situation.

Your operating data is yours. If you ever leave syteOn, we want that process to be clear rather than adversarial.

What we commit to today
{{ o.k }}
{{ o.v }}
Resilience & operations
{{ r.what }} {{ r.state }}
We're deliberately not publishing backup frequencies, recovery objectives, or uptime figures we haven't established and tested. When they're set, they'll appear here with numbers.
If something goes wrong
{{ i.num }} {{ i.step }}

Specific notification timelines and contractual commitments live in our agreements rather than on a marketing page.

Retention periods, deletion windows, export formats, and subprocessor lists are governed by our Terms, Privacy Policy, and — where applicable — a Data Processing Addendum. Ask us and we'll send the current documents rather than paraphrase them here.
Straight answers

The questions buyers actually ask.

Including the ones where the answer is no.

{{ f.q }} {{ f.verdict }}

{{ f.a }}

Trust the system you're asking to run the company.

Have a security, data, integration, or permissions question? We'll walk through how syteOn handles your specific operating environment — and tell you plainly where we're still building.

Talk to Us About Security Book a Walkthrough
Documents available on request
{{ d.what }} → {{ d.what }} {{ d.state }}
Larger operations often need a security questionnaire completed. Send yours and we'll answer it honestly, including the gaps.