Security & trust
This page says what Tobren Deliver and Tobren Operations actually do to keep your account, your files and your clients’ data safe — and, at the end, what we do not have yet. Every line describes something that is built and running today. Where the two products differ, it says which. Operations is not for sale yet; its entries describe the product as it stands ahead of launch.
1. Your account
- Sign in with Google, Apple, or a password you set yourself. Both products. One Tobren account works across Deliver and Operations.
- Two-factor authentication with an authenticator app, and recovery codes you download when you turn it on. Recovery codes are stored hashed and each works once. If you lose the authenticator, a “Lost your authenticator?” path gets you back in with a recovery code or a code sent to your email. Both products.
- We ask you to confirm it is you — your password, or a fresh Google or Apple sign-in — before you change your sign-in email, change two-factor, make new recovery codes or sign out everywhere. Our support team cannot make those changes for you. Deliver.
- An organization can require two-factor for everyone in it, and an owner can reset a member’s two-factor. Operations.
- Sign out of every device at once. Operations: everyone, from your profile. Deliver: from the studio’s settings today.
- Email alerts when two-factor is changed on your account or a recovery code is used. Deliver.
- Invitations are addressed to an email identity, not to whoever holds the link. You accept after signing in with the invited address; invite tokens are single-use and expire. Both products.
2. Your data is separated from everyone else’s
- Each studio or organization is isolated at the database level. Every table that holds customer data carries row-level security, enforced by the database itself rather than by a filter in the application that someone could forget to write. Both products.
- The isolation is tested against a database role that cannot bypass it: the test suite proves a cross-tenant read and a cross-tenant write are both refused. Both products.
- The database is reachable only on a private network and only over encrypted connections.
3. Your files
- Storage buckets are private. Public access is prevented at the bucket level; no file has a public URL.
- Files are served through short-lived signed links — fifteen minutes for gallery media, and at most an hour for anything else — so a link that is copied or forwarded stops working. Deliver.
- Restricted galleries are never search-indexed and are left out of the sitemap. Gallery passwords are stored hashed, and a gallery’s private link can be rotated. Deliver.
- Client share links (when a studio allows them) carry no-index headers, are stored hashed, can expire, and can be revoked. Deliver.
- The watermark never touches your original. It goes on a separate preview rendition. Deliver.
- Hidden metadata is stripped by default: location and editing-software tags come off photos and video as they are uploaded; camera, date and copyright are yours to keep or remove. Deliver.
- Filenames are hidden on public galleries by default. Right-click can be disabled per gallery; treat that as a deterrent, not protection. Deliver.
4. Payments
- Your clients pay you, not us. Checkout runs as a hosted Stripe Checkout session on your own connected Stripe account, or a hosted Square checkout on your own Square account. The money goes into your account; Tobren is never in the flow and never sees a card number. Deliver.
- Your own subscription card is entered through Stripe’s own card field. It never touches our servers.
- Connected-account tokens and mail-server passwords are encrypted in our database with a key held outside it. Deliver.
- Operations does not take client card payments at all; it produces quotes and invoices.
5. Encryption and transport
- Everything is stored on Google Cloud and encrypted at rest by Google’s default encryption. That is Google’s key management, not a Tobren feature, and we say so.
- TLS 1.2 or newer is required on both products, including on custom domains; older protocols are refused. HSTS is on for a year, including subdomains.
- Two-factor secrets are encrypted in the database; gallery passwords and share tokens are stored as hashes.
6. Privacy and your rights
- We never sell your media or your clients’ data, and never use it to train AI models. Both products. See the Privacy Policy.
- Deletion requests. In Deliver, a client can request deletion of their own data from their account; the studio sees the request in a queue and actions it, with a 30-day target. Order and payment records survive it, as the law requires, with the person anonymised. In Operations, deletion is by request to us, on the same 30-day target.
- Your data comes out. Deliver: a self-serve export, kept for 14 days. Operations: the owner can export the whole workspace as a ZIP, the registers as CSV and each pilot’s logbook as CSV or PDF.
7. Backups and continuity
- The database is backed up daily, seven backups are kept, and point-in-time recovery is on. Both products.
- We have restored from backup on purpose, as a drill, most recently on 2026-06-06.
- A public status page: status.tobren.io shows whether Deliver, Operations and the shared sign-in are up, with the recent history. Both products.
- Recovery times are targets we hold ourselves to, not contractual guarantees. See section 9.
8. When Tobren staff touch your workspace
- Operator access needs a written reason first, and every access is written to an append-only log whose entries are chained by hash, so a line cannot be altered or removed without breaking the chain. Both products.
- An operator acting in your workspace cannot perform sensitive account actions on your behalf — changing your sign-in email or two-factor, for instance. Deliver.
- In Operations, a change to your organization’s compliance records made by Tobren support is shown in your activity log, labelled as support.
- Tobren’s own administrators sign in with Google or Apple only.
9. What we do not have yet
Read this before you move a season of client work or a fleet’s history.
- No separate backup of uploaded files. Storage is redundant within Google Cloud, but we do not keep a second, independent copy of your media the way we do the database. Keep your own originals.
- A single-zone database. An outage of that zone means downtime until we restore, not an automatic failover.
- No third-party certification. We have not been through a SOC 2 or ISO 27001 audit.
- No formal uptime SLA.
10. Reporting a security problem
Email contact@tobren.io with what you found and how to reproduce it. A person reads it, and we will tell you what we did about it.