PowerOps includes access controls and attributed workflow approvals for generator service records, including ATS inspections, load bank results, and transfer switch service history. This page describes those controls and their limits. Review the evidence for your deployment before relying on a security or compliance claim.
When assigning a role or changing an individual override, review the sections and approval actions that the account needs, then test the resulting access with that account because protected business actions enforce effective permissions on the server rather than relying on the visible controls alone. High-value approvals also require re-authentication. The configurable defaults are $10,000 for invoices and $50,000 for quotes.
Audited workflow gates record the authenticated approving account, server timestamp, state change, and captured record snapshot. Application roles cannot update or delete those audit entries. A reversal adds a new entry with a reason. These records document approval; they do not independently prove that the underlying field work or readings are correct.
Business records are scoped by tenant or by a tenant-checked parent record. Server checks and database row-level security restrict access across companies. Automated tests cover cross-tenant cases; database-backed tests require a running test environment. Review deployment-specific verification as part of your security assessment.
Card details are entered on Stripe-hosted payment surfaces. PowerOps stores payment references and status, not card numbers. QuickBooks connection tokens are held in server-restricted storage. Review hosting, transport, and storage configuration during a deployment security review.
Photo analysis and compliance-report assistance return drafts for human review. An authorized person must verify the source records, findings, and proposed actions. AI output does not substitute for a technician’s judgment or an audited workflow approval.
PowerOps uses Vercel, Supabase, Stripe, Twilio, and Resend for hosting, data, payments, and communications. Field drafts are bound to the signed-in identity. Saving or reopening a draft requires online session verification; check the saved confirmation and reconnect to resume or submit. Drafts are never submitted in the background. Audited completion requires an authenticated connection.
PowerOps does not hold a SOC 2 attestation. This page makes no uptime guarantee and does not claim that software controls certify regulatory compliance or the accuracy of customer-submitted field evidence.
Ask for the scope and supporting evidence for the controls that matter to your organization. Procurement teams can send a security questionnaire through the contact page or bring it to a demo.
PowerOps does not hold a SOC 2 attestation. Infrastructure providers publish their own compliance documentation; their certifications do not certify PowerOps. Bring your security questionnaire to a demo to review the implemented controls and the evidence available for your deployment.
Audited workflow gate entries are append-only for application roles. They retain the approving account, server timestamp, state change, and captured record snapshot; reversals add a new entry with a reason. This protection applies to the audit entry and does not establish the accuracy of the field evidence or guarantee third-party acceptance.
Business data is scoped to a tenant or through its owning record. Server-side checks and database row-level security restrict access. The repository includes cross-tenant regression tests, including tests that require a running database; test coverage is not a guarantee against every possible access defect.
Roles and individual permission overrides control access to business sections, with levels for reading, acting, approving gates, and configuration. Server-side permission checks enforce protected actions. Supported permission-management actions write audit entries so changes can be reviewed.
By Stripe. Card details are entered on and processed by Stripe; PowerOps never stores card numbers. Integration credentials, such as QuickBooks tokens, are stored server-side in tables browser sessions cannot read.
Photo analysis and compliance-report assistance produce drafts for human review. AI output can be inaccurate or incomplete and must be checked before use. Audited workflow approvals and permission changes remain actions for an authorized person.
The fastest way to evaluate the audit trail is to watch it get written.