Company scoped authorization
Protected records are associated with a company identifier and signed in membership is checked before supported server operations read or change workspace data.

Security and operational trust
Sharpley Pro is designed to keep each company’s operating records inside its authenticated workspace. This page explains the controls currently used, the role of service providers and the responsibilities that remain with each customer.
Protected records are associated with a company identifier and signed in membership is checked before supported server operations read or change workspace data.
Each user signs in through an individual authenticated account. Workspace owners and administrators manage who is added and what role is assigned.
Owner, administrator, manager, sales, accounting and staff roles support different operational responsibilities. Customers remain responsible for assigning appropriate access.
Stripe hosts subscription checkout and processes card details. Sharpley does not store full card numbers or card security codes in company workspace records.
The application uses managed hosting and database services. Access to production services is limited to the systems and operators needed to run and maintain Sharpley.
Authorized users can upload job images and produce documents or exports. Customers should avoid uploading unnecessary sensitive information and should protect downloaded files.
Backups and recovery
Sharpley uses managed database recovery, daily company snapshots and protected file copies. Billing suspension does not delete a company workspace. Restoring payment reconnects the retained company information, records, files and documents.
Customer responsibilities
Use unique credentials, protect sign in devices, add only authorized users, review roles, remove former team members promptly, verify exported files before sharing and never place passwords, card details or API keys in business records or support chats.
Incident response
Customers should report unexpected access, unusual account activity or suspected data exposure through the Support page. Include the affected workspace, page, approximate time and visible behavior without sending passwords or payment card details.