TradieView ships granular, scope-based access control with an append-only audit log. This page is the source of truth for your IT-security team during procurement.
16
Capability scopes
7
Role bundles
99
Endpoints under scope control
365d
Audit log retention
Trusted by procurement teams across Australia
“TradieView passed our procurement sec-review in one round — every scope had a documented owner.”
“The append-only audit log was exactly what we needed for our SOC 2 vendor questionnaire.”
“The evidence pack landed within minutes of asking. That alone shortcut three back-and-forth emails.”
Frameworks
Data residency
Australia (AWS Sydney) — primary; encrypted-at-rest backups in ap-southeast-2.
Encryption in transit
TLS 1.2+ enforced on all customer-facing surfaces.
Encryption at rest
AES-256 via managed MongoDB Atlas (server-side).
Every super-admin action is gated on one of these capability scopes. Viewers are granted only the scopes they need.
Access Admin
Grant + revoke other superadmin viewers
Audit Logs
View platform audit log
Billing Read
View billing dashboards (read-only)
Billing Write
Mutate Stripe overrides, finance settings, subscription plan assignments
Company Admin
Read-only company directory + impersonation
Cron Ops
Pause / resume / force-run APScheduler jobs
Gdpr Bulk Export
Download the platform-wide GDPR/CCPA bulk ZIP
Infra Ops
Disk-space watchdog + emergency cache cleanup
Investor Invites
Mint / revoke investor teaser invites
Messaging Setup
Per-tenant messaging setup wizards
Ops Inbox
Read + acknowledge Ops Inbox alerts (margin / disk / addons / dispatch)
Scope Delegation Admin
Delegate scope grants to other viewers (limited to scopes the delegator already has)
Security Leads
View inbound security evidence-pack lead inbox
Sendgrid
SendGrid quota + sender domain controls
Twilio
Twilio messaging settings + provisioning
Web Maintenance
Site content + welcome page assets
Pre-vetted combinations for common team archetypes — granted with one click.
Compliance Officer
4 scopes
Audit trail + GDPR bulk export + finance reads for incident triage + security evidence-pack inbox.
Engineering On-call
4 scopes
Cron + infra ops + Ops Inbox + API surface map. The 3am-pager bundle.
Finance Viewer
2 scopes
Read billing dashboards + addon MRR + finance analytics. Read-only.
Investor Relations
2 scopes
Mint / revoke investor teaser invites + view their open log.
Marketing Lead
4 scopes
Manage investor invites + messaging templates + dispatch live tap + security evidence-pack inbox.
Ops Admin
4 scopes
Manage crons + disk watchdog + Ops Inbox alerts. Day-to-day platform operator.
Read-only Observer
2 scopes
Every read-only scope. Good for board / advisor accounts.
Append-only record of every privileged action. The platform owner reviews aggregate stats monthly.
Retention
365 days rolling window
Scope
Every super-admin grant, revoke, role change, and scope-level decision is recorded with actor email, target email, before/after scope diff, and ISO timestamp.
Owner review cadence
Monthly digest delivered 1st of each month at 08:00 UTC.
Tamper protection
Append-only collection; mutations forbidden by application layer.
Need our SOC 2 readiness letter, ISO 27001 controls mapping, or DPA template for your procurement file? Drop your work email and we'll send the pack within one business day.
Found a vulnerability? We'd love to hear from you. We commit to triage within 7 days.
security@tradieview.comWe use cookies. Details
We use essential cookies to keep you signed in and to keep the platform secure. We also use optional analytics and marketing cookies to understand how the site is used and to personalise what you see. You can change your mind anytime. For detail see our Cookie & Tracking Notice.