Security at PatrolBot SA
Patrol data shows where guards are and when sites are unprotected, so we treat it as sensitive. Here is how we protect it, and how to tell us about a problem.
How we protect your data
- Personal logins with two-step sign-in: a password plus a code on WhatsApp or from an authenticator app, or a passkey (fingerprint, face or phone PIN) that can't be phished. You get a WhatsApp message every time you sign in somewhere new, and can sign out other devices.
- SIM-swap protection: when WhatsApp reports that someone's account moved to a new phone, their supervisor is asked to confirm it's really them; until then their check-ins are flagged and sign-in codes to that number are paused.
- Roles: managers control people, logins and settings; supervisors and control rooms see what they need for the day's work.
- Separation: each security company sees only its own data; supervisors see their own sites.
- Encryption: all traffic is encrypted (HTTPS); photos are encrypted before they're stored, with a separate key per company; passwords and PINs are stored only as salted hashes; authenticator keys are encrypted.
- Protection against guessing: attempts are counted and accounts lock after repeated wrong passwords, PINs or codes.
- Tamper-resistant evidence: signed checkpoint tags, one-time verification links, forwarded messages and map-picked locations rejected.
- Tamper-evident audit trail of changes made in the console, with the person who made them: any edited or deleted entry is detected.
- Keeping data only as long as needed: patrol records are deleted automatically after about 12 months and incidents after 24, unless a case is still open.
- Secure development: automated tests for security rules, dependency checks before every release, and regular security reviews.
- Lost or stolen phones can be blocked immediately from the console or WhatsApp.
Report a security problem
If you think you've found a security problem in PatrolBot SA, please email [email protected] with enough detail for us to reproduce it.
- We'll reply within 3 working days and keep you updated until it's fixed.
- Please don't access, change or delete other people's data, disrupt the service, or share the problem publicly before we've fixed it.
- If you act in good faith and follow these rules, we won't take legal action against you for your research.
Machine-readable contact details: security.txt.