Security Overview

This is a plain-language description of the current pilot, not a certification, guarantee, or substitute for your own vendor review.

Infrastructure and transport

Board access model

Crew boards do not use a conventional username/password account. The admin recovery key is a high-entropy bearer secret: the raw key is stored in the admin’s browser, while the server stores a SHA-256 hash for verification. Worker links contain a separate high-entropy token. The worker token is stored with the board so an authorized admin can retrieve the link again.

Practical consequence: anyone who obtains an admin key can administer that board, and anyone who obtains a worker link can record events for that worker. Send links individually, do not post them publicly, and permanently delete a board if its access links are no longer trusted.

Input and export protections

Location and background access

The crew check-in page does not request GPS, microphone, camera, contacts, or background permissions. A future location feature should not be inferred from older marketing copy; it is not part of the current crew data flow.

Known limitations

Deletion

An authorized admin can permanently delete the board from the admin screen. This invalidates its crew links and removes the application record. Provider backups and security logs may age out on provider schedules rather than instantly.

Appropriate use

Do not use CheckInForWork as an emergency-response system, a clinical or protected-health-information system, a certified-payroll system, or the only control for work where a missed check-in could signal imminent danger.