1. Our Security Commitment
GuardSphere is built for companies whose business is protecting people and property, so we hold our own platform to the same standard. Schedules, incident reports, guard locations, client sites, post orders and payroll records are sensitive operational data, and we design every module — Scheduling & Time Tracking, Incident Reporting, Post Orders, Messaging & Alerts, Client Portal, Payroll & Labor Analytics, the Mobile Guard App and AI Intelligence — with security and privacy built in from the start.
This page describes the safeguards GuardSphere, a company incorporated in the State of Delaware, applies or is implementing as the platform moves from pre-launch to general availability. Specific commitments for Customers will be set out in their subscription agreement.
2. Infrastructure and Hosting
- Hosted on established cloud providers with physically secured, access-controlled data centers in the United States
- Network segmentation, firewalls and managed edge protection against denial-of-service attacks
- Separation of production, staging and development environments; production data is not used for testing
- Automated, encrypted backups with periodic restore testing
- Infrastructure changes are version-controlled and reviewed before deployment
3. Encryption
- Data in transit is encrypted with TLS 1.2 or higher, across the website, platform, Client Portal and Mobile Guard App
- Data at rest — including databases, file storage, photos and backups — is encrypted using AES-256 or equivalent
- Secrets and keys are stored in managed key and secret stores, never in source code
- Passwords are never stored in plain text and are protected with modern salted hashing
4. Access Control and Authentication
GuardSphere uses role-based access so each person sees only what their job requires:
- Customer roles such as owner, administrator, dispatcher, supervisor, guard and client, each with distinct permissions
- Clients in the Client Portal see only the sites, reports and activity their security provider shares with them
- Guards on the Mobile Guard App see only their own shifts, posts and assigned instructions
- Database-level row security isolates each Customer's data from every other Customer
- Support for strong passwords and multi-factor authentication, with single sign-on planned for Enterprise
- Session timeouts and the ability for administrators to revoke users and devices immediately
Internally, GuardSphere personnel receive least-privilege access, access is logged, and production access requires a business need and is reviewed regularly.
5. Application Security
- Secure development practices, peer code review and automated dependency and vulnerability scanning
- Input validation and protections against common web risks such as injection, cross-site scripting and request forgery
- Server-side enforcement of permissions — never relying on the browser alone
- Periodic security testing, with independent penetration testing planned before general availability
- Prompt patching of critical vulnerabilities in our code and third-party components
6. Mobile Guard App and Location Data
Location and field data deserve special care:
- GPS location is collected for clock-in, clock-out, patrol check-ins and active shift verification — not for off-duty tracking
- Customers control location settings and are responsible for giving guards required notice and obtaining consent
- Photos, video and incident evidence are uploaded over encrypted connections and stored encrypted
- Lost or replaced devices can be signed out remotely by an administrator
- Panic and escalation alerts are prioritized but depend on device, network and carrier availability — GuardSphere is not a 911 or alarm monitoring service
7. AI Security and Data Use
- AI features process Customer Data only to deliver the Services to that Customer
- Customer Data is not sold and is not used to train third-party public AI models
- AI providers we use are bound by contractual confidentiality and data-use restrictions
- AI outputs — severity ratings, summaries and recommendations — are designed to support human review, not replace it
- AI actions are logged so supervisors can see what was suggested and when
8. Logging and Monitoring
- Audit logs of key activity such as sign-ins, permission changes, report edits and data exports
- Tamper-resistant time and incident records to support investigations, client reviews and legal matters
- Continuous monitoring and alerting for unusual activity, failed sign-ins and system errors
- Log retention appropriate to security and compliance needs
9. Availability and Business Continuity
Security operations run 24/7, so the platform is designed for resilience: redundant infrastructure, automated failover where available, regular encrypted backups and documented recovery procedures. Planned maintenance will be scheduled to minimize disruption and announced in advance where practical. Service-level commitments, if any, will be stated in the Customer's subscription agreement.
10. Vendor and Subprocessor Management
We evaluate the security practices of vendors that process Customer Data, limit what data they receive, and require written confidentiality and security obligations. A list of subprocessors is available to Customers on request at info@guardsphere.net.
11. Our People
- Background checks for personnel with access to production systems, where permitted by law
- Confidentiality agreements for all employees, contractors, sales representatives and authorized dealers
- Security and privacy training at onboarding and at least annually
- Prompt removal of access when someone leaves or changes roles
12. Incident Response and Breach Notification
GuardSphere maintains an incident response process to detect, contain, investigate and recover from security events. If we confirm a security incident affecting Customer Data, we will notify affected Customers without undue delay and provide information they need to meet their own obligations. Where required, we will notify individuals and regulators in accordance with applicable U.S. state breach notification laws, as described in our Privacy Policy.
13. Compliance and Frameworks
Our security program is aligned with widely recognized frameworks, including the NIST Cybersecurity Framework, the OWASP Top 10 and the SOC 2 Trust Services Criteria. We are working toward independent attestations as the platform reaches general availability; GuardSphere does not currently claim any certification. Our practices are designed to help Customers meet U.S. state privacy and data security laws, labor recordkeeping requirements and their own clients' security requirements.
14. Shared Responsibility
Security is a partnership. Customers are responsible for:
- Assigning the right roles and removing users who no longer need access
- Using strong, unique passwords and enabling multi-factor authentication
- Securing the devices guards and staff use to access GuardSphere
- Giving required notices and obtaining consents for GPS, photos and monitoring
- Reporting suspected unauthorized access to us immediately at info@guardsphere.net
15. Reporting a Vulnerability
We welcome reports from security researchers. If you believe you have found a vulnerability, email info@guardsphere.net with the subject "Security Report" and include a description, steps to reproduce and any supporting details. Please give us reasonable time to fix the issue before disclosing it, avoid accessing or changing other people's data, and do not run denial-of-service, social engineering or physical attacks. We will acknowledge good-faith reports, keep you informed, and will not pursue legal action against researchers who follow these guidelines.
16. Contact Our Security Team
For security questions, questionnaires from your clients, or to report a concern, contact GuardSphere at info@guardsphere.net. Enterprise Customers may request additional security documentation under a confidentiality agreement.
This page may be updated as our security program evolves. Last updated: October 2, 2026.