Security
Security & data practices
Riser holds customer contact details, quote values and payment proof for stair runner businesses. This page describes the controls we have built into the product today.
How your account is isolated
Every record in Riser — customers, projects, staircases, quotes, invoices, payments, products and stock — is tagged to the account that created it, and the database refuses reads and writes that cross an account boundary. Teammates on your seats inherit your data through their seat, and their access ends the moment you remove the seat.
Sign-in
- Passwords are handled by our authentication provider and never stored by the app.
- Two-step verification with an authenticator app is available to every account, and owners can require it for all seats.
- You can end every other signed-in session from Settings if a device is lost.
- Client portal visitors sign in with a single-use emailed link, so customers never hold a password for your workspace.
In transit
The site and portal are served over HTTPS only; plain HTTP requests are redirected. We send strict transport security, content-type and framing headers, and a content security policy that restricts which scripts may run and which pages may be embedded on other sites.
Logging
Server logs pass through a redaction filter that removes passwords, keys and tokens before anything is written. Administrative actions and API calls are written to an append-only trail that cannot be edited or deleted from the app.
Keeping only what you need
Under Settings → Security & data, account owners choose how long activity logs, portal history, project messages, website enquiries, automation runs and error telemetry are kept. Anything past the limit is deleted automatically. Quotes, invoices, projects and customers are never auto-deleted, because you need them for your records.
Export and erasure
You can download your whole account as a single JSON file at any time. When one of your customers asks to be forgotten, log an erasure request and run it: names, contact details, notes, messages, enquiry forms and portal history are wiped, while the financial totals on quotes and invoices remain for your accountant.
Payments
Riser is bank-transfer first. We do not take or store card numbers — a customer uploads payment proof, and you approve or reject it. Uploaded files are private to your account.
Abuse protection
Public endpoints — the lead widget, shared quote links and the inbound API — are rate limited per caller, and inbound payloads are validated before anything is written.
Reporting a problem
If you believe you have found a security issue, please tell us through the contact form with the words "security report" in your message and enough detail to reproduce it. Please don't publish it until we've had a chance to respond.
Working out quantities before you quote? Start with the stair runner calculator, or see how the trade tools fit together in Riser for pros.