Privacy Policy
SilverCommand is operations software for security companies. Most of the data in it is not ours — it belongs to the security company using it, and it describes their officers, their sites, and their clients. This policy explains what we collect, why, and what we will and will not do with it.
Two roles, and they matter. When you visit this website or sign up for an account, SilverForge LLC is the controller of that data. When your security company uses SilverCommand to run its operations, SilverForge LLC is a processor — we hold and process officer, site, and incident data on your company's instructions. Your company decides what goes in, who can see it, and how long it stays. If you are an officer or a client of a security company and want your data changed or removed, start with that company; we will support their request.
1. Who we are
SilverCommand is a product of SilverForge LLC, a limited liability company based in Dayton, Ohio, United States. You can reach us about anything in this policy at support@silverforgellc.com.
2. What we collect
Account and billing data
- Name, work email address, phone number, job title and role of each user your company creates.
- Company name, business address, and the plan you are on.
- Payment details are handled by our payment processor. We never see or store full card numbers. We store only the processor's customer identifier, the last four digits, the card brand, and the subscription status.
Operational data you put into the system
- Sites, posts, shift schedules and assignments.
- Clock-in and clock-out events, including the post or site label recorded with them.
- Incident, daily-activity, maintenance, suspicious-activity and alarm-response reports, including the narrative text your officers write.
- Photos and documents uploaded as evidence, and site standard-operating-procedure files.
- Alarm records: type, site, dispatch time, arrival, resolution, and the officer involved.
- Equipment assignment and return records.
- Messages sent between users inside the application.
Technical data
- IP address, browser or device type, and timestamps, recorded in server access logs.
- Security and audit events: sign-ins, failed sign-in attempts, permission changes, and record deletions.
- Error diagnostics when something in the application fails.
Location data
SilverCommand records an officer's device location at specific moments, to verify they are where they say they are: when they clock in, when they clock out, and when they scan a patrol checkpoint or site visit. This is event-based, never continuous — by default, the application does not track a position between those moments, for any company.
Separately, the native mobile app supports optional continuous background location tracking while an officer is clocked in, so dispatch can see officer coverage on a live map. This is off by default at two independent levels, both of which must be true before anything is tracked: a security company must deliberately switch it on for their account, and each individual officer must separately agree to it on their own phone. Tracking always stops automatically the moment that officer clocks out, and any officer can withdraw their agreement at any time from their in-app settings. An officer whose company has not switched this on, or who has not personally agreed, is never tracked in the background, regardless of what the app is capable of.
3. What we do not do
- We do not sell personal information, and we never have.
- We do not share your operational data with advertisers or data brokers.
- We do not use your reports, photos, or officer records to train machine-learning models.
- We do not access your company's data except when you ask us to for support, when required to keep the service running, or when the law compels us.
- We do not run third-party advertising or analytics trackers on the application itself.
4. Why we process it
| Purpose | Basis |
|---|---|
| Providing the service you signed up for | Performance of our contract with you |
| Billing and account administration | Contract and legal obligation |
| Keeping the service secure and abuse-free | Our legitimate interest in a secure service |
| Support requests you raise with us | Contract and your consent |
| Meeting record-retention obligations | Legal obligation |
5. Who else touches the data
We keep the list of subprocessors deliberately short. As of the date above:
- Payment processing — a PCI-DSS Level 1 payment provider, for subscription billing.
- Email delivery — for invitations, password resets and system notifications.
- Hosting and infrastructure — the servers and backup storage the application runs on.
Each is bound by contract to process data only on our instructions. We will notify account administrators before adding a subprocessor that handles customer operational data.
We disclose data outside this list only when we are legally required to. If we receive a demand for a customer's data, we will tell that customer unless we are legally prohibited from doing so.
6. Security
- All traffic to and from the application is encrypted in transit with TLS.
- Passwords are stored as salted bcrypt hashes. Nobody at SilverForge can read them.
- Every tenant's data is scoped by company at the database query level, and access to another company's records is denied by default rather than filtered after the fact.
- Uploaded evidence files are stored outside any public web directory with randomised filenames and are served only through authenticated, permission-checked requests. There is no public URL for a report photo.
- Client portal accounts are restricted to the specific sites a security company grants them, and can see only reports that company has reviewed and approved.
- Invitation and password-reset links are single-use, hashed at rest, and expire.
- Backups are encrypted, and restores are tested.
No system is perfectly secure. If we discover a breach affecting your data, we will notify affected account administrators without undue delay and in any event within 72 hours of confirming it, with what we know and what we are doing about it.
7. How long we keep it
- Operational records (reports, alarms, shifts, evidence) are kept for as long as your company's account is active, because they are the record your company relies on.
- After cancellation, your data remains available for export for 30 days, then is deleted from live systems within a further 30 days.
- Encrypted backups roll off on their own schedule and are fully purged within 90 days of deletion.
- Billing records are kept for seven years, as tax law requires.
- Security and audit logs are kept for 12 months.
An account administrator can request an earlier full deletion at any time, and we will carry it out.
8. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a portable copy, object to certain processing, or withdraw consent. We do not discriminate against anyone for exercising these rights.
To exercise them, email support@silverforgellc.com. We respond within 30 days. If your data was put into SilverCommand by a security company — for example because you are one of their officers or one of their clients — we will refer your request to that company, since the data is theirs to control, and we will help them action it.
California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising.
EU/UK residents: where we act as a processor, the security company using SilverCommand is the controller and our data-processing terms apply. Any transfer of data out of the EEA or UK is made under Standard Contractual Clauses.
9. Cookies
The application uses a small number of strictly necessary cookies and browser storage entries to keep you signed in and to remember interface preferences. There are no advertising cookies and no third-party trackers. Because these are strictly necessary for a service you asked for, no consent banner is shown.
10. Children
SilverCommand is workplace software sold to businesses. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child's information has reached us, contact us and we will delete it.
11. Mobile applications
SilverCommand's native mobile app is in development and has not been released to officers yet. Officers currently use the service through a mobile web browser, which collects nothing beyond what is described above. When the native app is released, this section will be updated and account administrators will be notified beforehand. It will collect the same data described in section 2 above — including the optional background location tracking described there, which requires both a company-level opt-in and each officer's own consent on their own device — and nothing more. Any camera or location permission will be optional to grant and revocable in device settings at any time, and the app will contain no advertising SDKs and no third-party analytics.
12. Changes
If we change this policy in a way that materially affects you, we will email account administrators at least 30 days before it takes effect and update the date at the top. Continuing to use the service after that date means you accept the revised policy.
13. Contact
SilverForge LLC
Dayton, Ohio, United States
support@silverforgellc.com