← Back to Pipe Pilot
Security & Trust

Protection for workshop, customer and organ data.

This page summarizes the security and privacy controls used by Pipe Pilot. It is customer-facing project content and not an independent certification.

Private by default

Application data and files require authenticated access.

Organization-scoped

Access rules separate each workshop's records.

Role-aware

Administrative capabilities are limited to authorized roles.

Security controls

  • Authenticated access is required for the application area; public visitors only see landing and legal pages.
  • Workshop data is separated by organization so users only access records for their active company unless explicitly authorized.
  • Maintenance photos, organ-note files and documents are stored in private buckets and are delivered through temporary signed links.
  • User roles are stored separately from profile data and are checked by backend access rules rather than trusted from the browser.
  • Operational logs and administrative health views are restricted to authorized organization members or administrators.
  • AI-assisted features are designed to process only the task data needed for transcription, planning or photo analysis.

Privacy and data handling

Pipe Pilot is built for professional organ-building workflows and handles customer contacts, church and organ records, maintenance plans, reports, photos, notes and project information. For legal privacy details, see the privacy policy and data processing agreement.