Security

How we protect your crew’s details

Call sheets, phone numbers, W-9s and insurance certificates usually live in email threads and shared drives. The bar we hold ourselves to: they should be harder to get at here than they are there. This page says how, and what we have not done yet.

Signing in

A password is not enough to reach the sensitive parts.

  • Passwords are stored hashed, never in readable form. Email addresses are confirmed before an account works.
  • Two-step sign-in with an authenticator app (Google Authenticator, 1Password, Authy and the like).
  • Required for company owners and admins, for anyone opening another person’s paperwork, and for changing payment or payout details.
  • Checked by the database on every request, not only by the page. An owner whose session has not passed the second step gets nothing back from the money, team and paperwork tables.

Who can see what

Every table checks who is asking before it answers.

  • Access rules live in the database (row-level security) on every table, so a mistake in one page is not enough to show one company another’s data.
  • Company roles: Owner, Admin, Member and Viewer. Viewers can read but not post or reply. Seats are free, so there is no reason to share a login.
  • Holds are private to the company that made them. A company sees its own place in the queue, never who is ahead of it or what anyone else offered.
  • Post notes are marked for your shop, for you and the production company, or for everyone including the client. Each person only receives the notes their layer allows.
  • Cost rates, pay and profit are visible to owners and admins only, and only after two-step sign-in.

Crew paperwork

W-9s and certificates of insurance are the most sensitive thing here, so they get the strictest handling.

  • Files sit in private storage, in a folder only their owner can read.
  • Crew share each document with a specific company, and can take it back at any time.
  • Opening someone else’s document needs two-step sign-in. The link it opens with expires after 60 seconds.
  • Every open, share and take-back is written to a log: who, whose document, which company, and when. The log survives the file being deleted.
  • Company owners and admins can download that log as a spreadsheet for their own client’s audit.
  • Tax IDs on invoices keep only the last four characters. The database enforces it.

AI and your data

Used for matching crew to jobs, and kept away from anything sensitive.

  • Dayrate uses Anthropic’s Claude to score how well a job fits a person, and to read a resume someone uploads.
  • Anthropic’s commercial terms do not allow training on what we send. They keep it for a limited period for safety review, then delete it.
  • Phone numbers, email addresses and tax-ID-shaped numbers are removed before anything is sent.
  • Crew paperwork, roster phone numbers and company money are never sent at all.

Where it runs

Established providers, with data kept in the United States.

  • Database, files and sign-in: Supabase, on AWS in the United States. Encrypted at rest.
  • Website: Vercel. Background work (matching, reminders): Fly.io. Email: Resend. Payments, when used: Stripe.
  • Everything travels over HTTPS, with HSTS. Pages cannot be framed by other sites.
  • Our own background service is not reachable from a browser. Only the website’s server can call it, and every call carries a secret key checked on arrival.
  • Logs record ids and counts, not phone numbers or email addresses.

Keeping and deleting

You can leave, and your files leave with you.

  • Company owners and admins can download everything the company has put in as spreadsheets, any time: crew list, holds, invites, post notes, hours, money and the paperwork log.
  • Anyone can delete their account from Account and sign-in. Their uploaded files in every storage area are deleted with it.
  • The paperwork log is kept for two years, because that is what a client audit asks for. Security logs are kept for 90 days.
  • We do not sell data, and we do not run ads.

What we don’t have yet

Said plainly, so nobody finds out later.

  • A SOC 2 report. We are not audited yet.
  • An independent penetration test.
  • Single sign-on (SAML) for company accounts.
  • Recovery codes for two-step sign-in. Today a lost phone means a manual reset after we check who you are.

Questions from your client?

If a client’s security team has a questionnaire, send it to hello@itsdayrate.com and we will fill it in. The same address takes reports of a security problem; we answer those first.