Security & Responsible Disclosure
Effective August 1, 2026
How the service is protected
Cinder Spur for Detailers uses authenticated private workspaces, server-derived business scope, server-enforced roles and license state, business-prefixed file storage, restricted imports and restores, request identifiers, audit records, and fail-closed authorization checks.
Customer portal status
The public external customer portal is not included in the current launch. Customer-facing records remain available to the business owner through the private Customer View while the separate public-access architecture receives additional review.
What customers should do
Limit account access to approved people, review team roles, revoke departed users promptly, keep local exports, verify payment changes independently, and never share sign-in links, portal tokens, complete exports, or photo archives by ordinary email.
Report a security concern
Email support@cinderspur.com with the subject “Security report.” Include the time, affected page or action, browser, and a redacted description. Do not test another customer's workspace, retain accessed data, or include secrets, tokens, customer content, card information, or photo bytes.
Our response
Reports involving access, availability, suspected tenant exposure, or data loss receive priority review. Cinder Spur may request a safe reproduction using disposable records and will preserve relevant request identifiers and system evidence without copying customer content into ordinary support notes.
No certification claim
This page describes current product practices; it is not a claim of formal certification, a penetration-test warranty, or a guarantee that every security event can be prevented.