Security and trust

How we look after your firm's data, and what is not in place yet. For questions, email contact@profitdrive.app.

Where your data lives

Customer data is stored and processed in Singapore: the database runs on Supabase and background work on Render. The app's pages are delivered through Vercel's global network. This website and its sign-up data run in Sydney, Australia, on Vercel and Neon. Supabase and Vercel encrypt data in transit and at rest, and both hold SOC 2 Type 2 reports.

The answers you give when you request early access on this website are stored separately, in the website's database. Read the privacy policy

Separation between firms

Every table sits behind Postgres row-level security, so the database itself checks which firm a user belongs to on every read and write. Automated database tests, including tests that try to read another firm's data, run on every change before release.

Sign-in runs on Supabase Auth, and connection tokens are kept in an encrypted vault.

Who sees what

Every person in Profitdrive has a seat and a role. Together they decide what that person can see and change. The database checks these permissions on every request, so they do not depend on hiding buttons on screen. Automated tests sign in as every seat on every change before release.

Full. For the people who run the firm: complete financial control, including the P&L, cost and individual salaries.

Team. For people who run the work: pipeline, Deal Model, projects, people, utilisation and timecards, with revenue, cost, margins and daily rates. Individual salaries and the Finance area (P&L and SG&A) stay with Full seats. Level 1 includes operating margin and the board pack. Level 2 shows gross margin and contribution, and keeps operating margin back. The firm sets a default level and can change it per person.

Viewer. For board members or a CEO who need the full picture. Read-only, and free.

Partner. For your external accountant, an adviser or an investor. Read-only, and free.

Submitter. For people who only log time. They see their own timecards and nothing else. The first five are free.

Roles. The Owner manages billing and ownership. Power Users manage users and settings. Users work within their seat.

You decide what Viewers and Partners see

By default they see everything a Full seat sees, except individual salaries. For Viewers and Partners separately, the owner can switch off:

  • the Finance area (P&L and SG&A)
  • margins (revenue, cost and daily rates stay visible)
  • timecard detail (status and completeness stay visible)

The switches can only reduce access, never widen it.

Pay and approvals stay central

Salaries stay with Full seats. Annual pay and pay history are visible only on Full seats. Everyone else plans with a daily cost per person, so project managers can manage their projects without seeing anyone's pay.

Timecard approval stays central. Team members can see the status of every timecard and read colleagues' entries. Only the owner and Power Users approve timecards, reopen them, or accept a month into the actuals.

Accounting and payments

Xero connection. The Xero connection is read-only and set up by a Full seat. Profitdrive never writes anything back to Xero. More on integrations

Payments. Paddle is our merchant of record and holds SOC 2 Type 2 and PCI DSS Level 1. Your card details go to Paddle, and Profitdrive never sees or stores them.

Your data

  • You can export the P&L, reports and lists at any time.
  • If you ask us to delete your data, we delete it within 90 days, as set out in our privacy policy.
  • If a trial does not continue, the account becomes read-only and exports keep working. We keep the data for at least 60 days, and before we delete it we email the Owner at least a week ahead.

SOC 2 and sign-in

Our own SOC 2 audit is in preparation.

You can sign in with Microsoft or Google today; if that account uses multi-factor authentication, it protects your Profitdrive sign-in too. Company single sign-on (SAML) and multi-factor authentication inside Profitdrive are available on request.

See it with your own firm's data

Request early access