Security

Last updated: July 26, 2026

Overview

Sidecar Software Inc. ("Sidecar") builds software for local service businesses. Protecting your data is part of how we earn your trust. Security is an ongoing practice, not a one-time checklist. If you have questions about this page, contact us at support@sidecar.pro.

Infrastructure

Sidecar runs on modern cloud infrastructure:

  • Application hosting on Vercel with TLS for all traffic
  • Managed PostgreSQL for application data
  • Separate development, preview, and production environments

Authentication and Access Control

Access to Sidecar is gated at multiple layers:

  • Identity and authentication through WorkOS
  • Role-based permissions that limit what each team member can view or change
  • Organization-scoped data access so users only reach accounts they belong to

Data Protection

We use technical and organizational measures appropriate to the data we process:

  • Encryption in transit via HTTPS/TLS for all web and API traffic
  • Encryption at rest provided by our cloud infrastructure providers
  • OAuth and integration tokens encrypted with AES-256-GCM before storage in our database
  • Customer file attachments stored in a private object storage tier and served through authenticated application routes — not as public direct links

No method of transmission or storage is 100% secure. We work to protect your information but cannot guarantee absolute security.

Application Security

Our engineering practices include:

  • Dependency updates and code review on changes to production systems
  • Least-privilege credentials for services and integrations
  • Environment isolation so production secrets are not used in development

AI Data Handling

Sidecar uses AI to power automation features. Your customer and business data may be processed by AI models to generate suggestions and complete tasks. We do not use your data to train AI models without your explicit consent. You control which automations and assistant features are enabled in your account. See our Privacy Policy for more detail.

Monitoring and Audit

  • Error and performance monitoring to detect and respond to production issues
  • In-app audit log for account administrators to review significant account activity

Subprocessors

Sidecar relies on trusted third-party providers to deliver the service, including:

  • Vercel — application hosting and infrastructure
  • WorkOS — authentication and identity
  • Stripe — payment processing
  • Twilio and mobile carriers — SMS delivery
  • Anthropic — AI inference for assistant and automation features

These providers process data only as needed to perform their role in delivering Sidecar. See our Privacy Policy for how we share information with service providers.

Your Responsibilities

Security is shared. You can help protect your account by:

  • Using strong, unique passwords and enabling available account security features
  • Limiting administrative access to team members who need it
  • Reporting suspected unauthorized access or security issues promptly

Reporting Security Issues

If you believe you have found a security vulnerability or suspect unauthorized access to your account, email support@sidecar.pro. For privacy-related requests, contact privacy@sidecar.pro.