Private bucket
Project files are not stored in a public media library.
Security
Daily logs, photos, signatures, and change orders can contain sensitive project information. DailyLogsPro uses layered controls for stored files, account access, device sessions, and connected systems.
Stored files
Photos and generated PDFs are client-side encrypted using AES-256-GCM with AWS KMS. The private storage bucket receives ciphertext rather than ordinary readable files. This limits exposure if storage access is ever misconfigured or challenged.
Project files are not stored in a public media library.
AES-GCM protects confidentiality and detects unauthorized modification.
AWS KMS supports controlled key management for encrypted assets.
Accounts
DailyLogsPro uses Argon2 password hashing, short-lived access tokens, and refresh behavior designed to limit the usefulness of a stolen token. Users can view signed-in devices and revoke sessions remotely.
Integrations
PayAppPro connections begin with a one-time pairing code. Credentials are stored encrypted, and every server request is cryptographically signed with HMAC so the receiving service can verify its source and integrity.
Shared responsibility
Use individual accounts, assign the Admin role carefully, remove former employees promptly, and review device sessions. Do not share passwords or send sensitive project files through unsecured channels merely because the original record is protected inside DailyLogsPro.
Organization administrators should establish retention, access, device, and incident-response expectations that fit their contracts and risk profile.
Record integrity
Encryption protects stored files from unauthorized reading. Attribution, status locking, approval roles, and workflow history protect a different concern: whether the organization can understand who created, submitted, corrected, and approved a record. Both are necessary for trustworthy project documentation.
Explore the workflow
Consider how protected files, offline records, integrations, and account practices fit together across the complete workflow.
Questions
Yes. Photos and generated PDFs are client-side encrypted with AES-256-GCM using AWS KMS and stored as ciphertext in a private bucket.
Yes. Users can review active device sessions and revoke them remotely.
Only users with the Admin role can approve submitted daily logs.
Protect the project record
Contact us to discuss encrypted files, account roles, device sessions, record attribution, and signed integration requests.