Security & privacy
You are considering trusting a new company with the records that back your contracts and your insurance claims. That deserves specifics, not badges. Everything below describes how the software actually works — and where a limit exists, it is stated rather than papered over.
What we will not claim: SilverForge does not hold SOC 2, ISO 27001, or any third-party security certification today. Small companies that claim otherwise are lying to you, and vendors that bury this fact are hoping you will not ask. We would rather you knew. Certification is a roadmap item that follows revenue; the engineering practices below do not wait for it.
Tenant isolation
Every record in SilverCommand — every officer, site, shift, report, photo and alarm — carries your company's identifier, and every query filters on it at the database layer. Access to another company's data is denied by default, not filtered out afterwards: a request for a record outside your company returns nothing, exactly as if it did not exist.
Client portal accounts are one further ring out. They are blocked from every staff endpoint outright, and inside the portal they see only the specific sites your company granted them, and only reports your team has reviewed and approved. A client can never see a draft, an internal note, or another client's site.
Evidence handling
No public URLs
Uploaded photos and documents are stored outside any web directory under randomised names. There is no address that serves a report photo without an authenticated, authorised request.
Checked twice
Every file request re-checks both company scope and, for portal users, site access and report approval — the same rules as the report it belongs to.
Type and size limits
Uploads are limited to common image formats and PDF, 10 MB per file, ten files per report. Nothing executable is accepted.
In the record, permanently
Evidence is embedded into generated PDF reports, so what a client files with an insurer contains the photos — not links that might die.
Location data — what it is and is not
By default, SilverCommand records an officer's position at specific moments: clocking in or out, scanning a patrol checkpoint, arriving at or leaving a site. That part is event-based, never continuous — the software does not track anyone between those events, for any company, with no opt-in required.
Verification is honest about physics. Consumer GPS drifts, particularly indoors, so the system accounts for the device's own reported accuracy — while capping that allowance so a deliberately degraded reading cannot fake presence from far away. When a position cannot be confirmed, the record says unverified and a supervisor decides, with their decision and reason kept on record. An officer in a concrete stairwell is the normal case, not the fraud case, and the software is built on that assumption.
Separately, the native mobile app supports optional continuous background location tracking — a live breadcrumb trail while an officer is on shift, for dispatch's coverage map. This is off everywhere by default and requires two deliberate steps before it does anything: a security company must switch it on for their account, and each individual officer must independently agree to it on their own phone. It always stops automatically the instant that officer clocks out, and any officer can withdraw their agreement at any time from their own in-app settings. An officer whose company hasn't switched this on, or who hasn't personally agreed, is never tracked in the background.
Access control
- Six roles, from platform administration down to client portal accounts, enforced on every route on the server — never only in the interface.
- Passwords stored as salted bcrypt hashes. Nobody at SilverForge can read one.
- Invitations and password resets use single-use links that are hashed at rest and expire after 72 hours. Temporary passwords are never sent by email.
- Real-time updates are scoped server-side from the authenticated session — a connection cannot subscribe to another company's events regardless of what it asks for.
Your data is yours
The promise, in writing: you can export everything your company has put into SilverCommand at any time while your account is active, and for 30 days after cancellation. We claim no ownership of your operational records, we do not sell them, we do not share them with brokers, and we do not use them to train machine-learning models. If SilverForge ever ceased operating, the export exists precisely so your records outlive us.
Retention follows the Privacy Policy: operational records kept while the account is active, deleted from live systems within 60 days of cancellation, backups fully cycled within 90. An administrator can request earlier full deletion and we will carry it out.
Infrastructure, plainly
Traffic is encrypted in transit with TLS. The application and database run on infrastructure SilverForge operates directly rather than a shared multi-tenant platform, behind a hardened reverse proxy that strips server identification and enforces strict transport security. Databases are backed up nightly, and — the part most vendors skip — restores are actually tested, because a backup that has never been restored is a hypothesis.
Honest scale note: at this stage SilverForge does not publish an uptime SLA, because we will not promise a number we cannot yet evidence. What we commit to instead is responsiveness — see Support for the response times we hold ourselves to, and ask us anything about the architecture before you sign. The answers will be specific.
Reporting a vulnerability
Email support@silverforgellc.com with the subject Security report. We acknowledge within 24 hours, we will not pursue researchers acting in good faith who give us reasonable time to fix, and we will credit you if you want credit.