Your data is separate
Customers, sites, forms, and submissions are scoped to your organisation and kept separate from other tenants.
Tenant-scoped data
Try Door Ops free. No card. No automatic charge. Build better door-company software with us.
Free beta & paid plansSecurity and privacy
Door Ops keeps your business data scoped to your organisation. Control who can see what, and keep a traceable history of key actions.
Last 24 hours
Data isolation
Door Ops is designed so each organisation works in its own data scope.
Customers, sites, forms, and submissions are scoped to your organisation and kept separate from other tenants.
Tenant-scoped data
Each role sees only the forms and submissions they need. You decide who can create, review, and manage.
Role-based access
Key actions and submission edits are logged, including who edited what and when.
Useful for customer queries
Modern authentication, secure sessions, and protected browser access.
TLS-protected sessions
Access control
Each person sees only what they need to do their job. No more, no less.
Infrastructure
Modern controls for access, review, and accountability. Backups, recovery targets and what happens if we stopped are on the backups and continuity page.
Runs on Laravel Cloud in the London region with Cloudflare in front; photos and documents sit in EU-jurisdiction object storage. Daily database snapshots by the platform, restorable to a fresh copy without touching the live one. We aim for 99.9% availability and tell you about planned maintenance in advance.
Each firm's records are snapshotted separately each night and kept 30 days plus a monthly copy for a year, so we can restore one firm — or one firm's Tuesday — without touching anyone else.
Deleted records go to your Recycle bin first. Deleted photos and files are held for 30 days before removal.
Key user actions are recorded, including who edited what and when.
Owners export everything — a spreadsheet per record type plus every photo and PDF — from Settings, any time, no exit fee. UK GDPR access, erasure and portability requests are built in.
MCP uses OAuth with mcp:use. API keys are org-pinned and revocable. Agents never exceed the user’s role.
Last 24 hours
Audit trail
Who edited what, and when. Useful when customers or insurers ask questions.
We are happy to discuss security requirements for your business. Or start a trial and see for yourself.