WashOptic

Security

Trust starts with clear boundaries and auditable data.

WashOptic is designed to protect customer operating information while preserving the evidence behind each opportunity and measured outcome.

Security approach

Protection across access, infrastructure, and data handling.

Authenticated application access

The customer application requires authenticated access; the public marketing site does not provide customer-data access.

Organization and role boundaries

Access is designed around organization membership and assigned roles so users see the areas authorized for their work.

Secure hosted infrastructure

WashOptic uses managed hosting and infrastructure controls designed to support secure operation, monitoring, and maintenance.

Server-side credentials

Credentials used for future approved integrations are intended to remain on the server rather than being exposed in the browser.

Raw import preservation

Imported source files and mapping context can be retained to support traceability, troubleshooting, and auditability.

Transparent limitations

Missing or unmapped inputs remain missing; the system does not turn absent evidence into a zero.

Tenant isolation

Customer data is kept within its organization context.

The authenticated application is designed to scope access by organization and role. Customer-uploaded operational data is used to provide the service and is not public.

Certifications

WashOptic does not claim SOC 2, ISO, or another formal security certification unless and until that certification has been obtained and can be substantiated.

Responsible disclosure

Report a potential security issue.

Email tinman@tinmenenterprises.com with the subject “WashOptic Security Report.” Include a clear description, affected location or feature, reproduction steps, and supporting evidence. Please avoid accessing or changing data that is not yours, disrupting the service, or publicly disclosing an issue before we have had a reasonable opportunity to investigate.