Security and privacy
What stops one customer from seeing another customer's data.
It is not a check in the application code. It is a database policy, enabled on every table, with an automated test proving an anonymous user reads nothing.
Isolation by database policy
Every operational table carries the organisation and has row-level policy enabled. Even if the application has a defect, the query comes back empty — the barrier sits below the code.
The application has no master key
The production environment deliberately does not receive the database service key. Every access goes through the user's own session, so the policy always applies. That is not an oversight: it is a recorded decision.
Roles and access matrix
Four roles, plus the ability to switch individual pages on or off per person. An executor only sees the tickets they are involved in.
Per-site scoping
A person linked to a site sees that site. With no link, they see all of them — the default is explicit, not implied.
An audit trail that cannot be erased
Append-only record of changes to the registry, assets, preventive plans and costs. There is no delete policy: records are deactivated, never removed.
Headers and transport
HSTS with preload, a content security policy, frame-embedding blocked and no MIME sniffing. Certificate issued and www redirected to the apex domain.
Personal data
The system stores names, emails and phone numbers for team members and suppliers — the minimum needed to operate. None of it goes to logs, and phone numbers and admin notes live in a separate table visible only to administrators.
Public sign-up disabled
Nobody creates an account on their own. Users are created by an organisation administrator, with a record of who created them and when.
Your documents and questions stay yours
Manuals, reports, checklists and questions to the agent are indexed inside your organisation, and search only reaches what belongs to you. None of it feeds another customer's knowledge base. If we ever build a shared technical library, it will require written authorisation, carry no private data, and never identify its source — and never by default.
Data protection (LGPD)
Manutex processes personal data of team members and suppliers on behalf of the customer, who is the controller. Legal basis, purpose and retention period are set in the contract. Export and deletion at the controller's request are provided for.
Ready to get maintenance out of WhatsApp?
A 30-minute conversation and a demo using your operation's real data, not sample data.
Create your account, upload your spreadsheets and WhatsApp group — the system arrives already set up. No credit card.