Security
Confidentiality is a property of the data, not a promise in a policy
SpecLatch exists because one record serves three audiences — engineering, partners, and the public. Try it: switch the audience and watch the same record redact itself. Below, how that separation is enforced, mechanism by mechanism.
Distributor — portal & quotes: 5 of 6 fields shown. The supplier stays confidential.
The mechanics
Per-field visibility tiers
Every field is public, internal, or confidential — set on the field definition, inherited by every record. The tier is checked by the database layer on every surface that reads data: the grid, generated PDFs, the public portal, search, exports, and the API. There is no separate "website copy" of your data to drift out of sync.
Organization-scoped isolation
Every row in the database carries its organization. Every query filters by it — a rule enforced in one shared data-access layer and covered by tenant-isolation tests, not re-implemented per feature.
Roles, and keys that can't overreach
Members get roles with tier ceilings — a viewer capped at internal can't see confidential fields no matter what screen they're on. API keys are read-only and tier-scoped: a key minted for your website can only ever read published, public-tier data.
An approval workflow between draft and published
Records move draft → review → published. The public portal and the read API serve published records only, so half-finished engineering work is structurally kept off customer-facing surfaces.
Where your data lives
Application data lives in PostgreSQL and uploaded files in object storage, both in managed cloud infrastructure with automated backups. Passwords are handled by our authentication provider (Clerk) and never touch our servers; billing cards are handled by Stripe the same way.
Export is always available
A full export of your organization — every table, record, link, and document reference — is one click, in XLSX. That stays true even if your subscription lapses: your data is yours, in formats that outlive any vendor.
Certifications & compliance
SpecLatch doesn't yet hold formal certifications like SOC 2. What it offers instead is an auditable system where the confidentiality rules above are code — covered by an automated test suite that runs on every change.
Questions about how any of this works — or requirements we should know about before you join? Ask directly: hello@speclatch.com. You'll get an engineer's answer.