TRUST & SECURITY

Your maintenance records deserve serious protection.

Security should be clear enough to understand and specific enough to verify. Here is how Maintain CMMS protects your information across accounts, application access and private data storage.

HOW YOUR INFORMATION IS HANDLED

Practical controls—not vague promises.

Maintain CMMS combines application-level safeguards with managed network, database and private object-storage controls. Access decisions remain inside the application and are checked again on protected server routes.
01

Encrypted connections

Maintain CMMS is served exclusively over HTTPS, protecting information while it travels between your browser and the service.

02

Edge and network protection

Traffic passes through a managed edge network that provides DDoS mitigation and network-level traffic screening before requests reach the application.

03

Browser security policy

Security headers prevent framing, MIME-type guessing and unnecessary browser access to sensitive device capabilities, while limiting cross-origin data exposure.

04

Protected passwords

Passwords are never stored as readable text. Each password is individually salted and processed with PBKDF2-SHA-256 before the result is stored.

05

Secure sessions

Sign-in tokens are generated with cryptographically secure randomness, stored as hashes and sent in Secure, HttpOnly, SameSite cookies.

06

Account protection

Repeated failed sign-in attempts trigger a temporary account lock. Login responses avoid revealing whether an email address is registered.

07

Organisation separation

Application requests are checked server-side against the signed-in user’s organisation and role. Records are queried within that organisation boundary.

08

Roles and audit history

Owner, administrator, manager, technician and requester permissions limit sensitive actions. Important operational changes are retained in the application audit history.

09

Controlled file access

Uploaded documents and evidence use private object storage and are retrieved through authenticated, organisation-scoped application routes.

10

Authenticated service email

Maintain CMMS service email is authenticated with SPF and DKIM. A rejecting DMARC policy tells receiving systems to block messages that fail the domain's authentication checks.

11

Portable data architecture

Core business records use a structured database and the platform is designed around exportable data, documented migrations and replaceable hosting services.

YOUR DATA

Private by default.
Exportable by design.

Maintenance records are associated with an organisation workspace. Uploaded files are not intentionally published as open web assets, and protected routes check identity and organisation membership before returning customer information.
  • Customer passwords are not stored in readable form
  • Session tokens are not stored in readable form
  • Secrets stay outside the source code
  • Customer records are designed to remain exportable
  • Hosting services are kept replaceable where practical

RESPONSIBLE DISCLOSURE

Found a security concern?

Please do not test against customer data or disrupt the service. Send enough detail for us to reproduce the issue and we will investigate it directly.
Email hello@maintaincmms.com →

STRAIGHTFORWARD SOFTWARE. STRAIGHTFORWARD ANSWERS.

Ask us about your security requirements.

If your organisation has a security questionnaire, retention requirement or access-control policy, speak to us before creating your workspace.Talk to Maintain CMMS →

READY TO GET MAINTENANCE UNDER CONTROL?

Choose your plan. Create your workspace. Start today.

Pick the functionality level you need, create or sign in to your account, accept the terms and complete secure checkout. Your paid features unlock automatically.
Choose a plan & sign up →Try free firstNo per-user fees · No per-asset fees · Secure Stripe checkout