Security

Protect the records your company may need to defend.

Daily logs, photos, signatures, and change orders can contain sensitive project information. DailyLogsPro uses layered controls for stored files, account access, device sessions, and connected systems.

Stored files

Encrypt photos and generated documents before storage.

Photos and generated PDFs are client-side encrypted using AES-256-GCM with AWS KMS. The private storage bucket receives ciphertext rather than ordinary readable files. This limits exposure if storage access is ever misconfigured or challenged.

Private bucket

Project files are not stored in a public media library.

Authenticated encryption

AES-GCM protects confidentiality and detects unauthorized modification.

Managed keys

AWS KMS supports controlled key management for encrypted assets.

Accounts

Use modern authentication and visible device control.

DailyLogsPro uses Argon2 password hashing, short-lived access tokens, and refresh behavior designed to limit the usefulness of a stolen token. Users can view signed-in devices and revoke sessions remotely.

  • Individual user accounts preserve attribution
  • Admin and Member roles limit approval authority
  • Email invitations place new users into the correct organization
  • Device sessions can be reviewed and revoked
  • Submitted and approved records retain who and when

Integrations

Sign requests between connected systems.

PayAppPro connections begin with a one-time pairing code. Credentials are stored encrypted, and every server request is cryptographically signed with HMAC so the receiving service can verify its source and integrity.

Shared responsibility

Security also depends on company account practices.

Use individual accounts, assign the Admin role carefully, remove former employees promptly, and review device sessions. Do not share passwords or send sensitive project files through unsecured channels merely because the original record is protected inside DailyLogsPro.

Organization administrators should establish retention, access, device, and incident-response expectations that fit their contracts and risk profile.

  • Require individual sign-in
  • Limit administrator access
  • Review organization membership
  • Revoke lost or replaced devices
  • Use approved export and sharing methods
  • Report suspicious access promptly

Record integrity

Protect both confidentiality and the history of action.

Encryption protects stored files from unauthorized reading. Attribution, status locking, approval roles, and workflow history protect a different concern: whether the organization can understand who created, submitted, corrected, and approved a record. Both are necessary for trustworthy project documentation.

Explore the workflow

Review security in the context of real work

Consider how protected files, offline records, integrations, and account practices fit together across the complete workflow.

Questions

Frequently asked questions

Are photos encrypted?

Yes. Photos and generated PDFs are client-side encrypted with AES-256-GCM using AWS KMS and stored as ciphertext in a private bucket.

Can a user revoke a lost device?

Yes. Users can review active device sessions and revoke them remotely.

Who can approve a daily log?

Only users with the Admin role can approve submitted daily logs.

Protect the project record

Review DailyLogsPro security with your team.

Contact us to discuss encrypted files, account roles, device sessions, record attribution, and signed integration requests.

Contact Sales