Security & trust

A security posture you can verify, not just trust.

CIDSync touches a deliberately narrow slice of your business, your phone numbers and the credentials to keep them registered, with least-privilege access, encrypted credentials, database-enforced tenant isolation, and preview-first writes. Here is exactly how, in the detail your IT, finance, and operations reviewers ask for.

How your data is handled

The controls, in specifics.

Credentials encrypted with AES-256-GCM

ServiceTitan and Hiya credentials are sealed in versioned AES-256-GCM envelopes bound to your exact tenant, provider, and environment, so a copied ciphertext will not open anywhere else. Only the sync runtime holds the key; every dashboard, log, and staff screen sees a fingerprint, never the secret.

Read-only at the source

CIDSync only issues read requests to ServiceTitan. It never writes jobs, invoices, estimates, dispatch records, customer records, or accounting data back.

Database-enforced tenant isolation

Every record is walled off by Postgres row-level security, and credential ciphertext is readable only by the service runtime, not by any signed-in user, including yours.

API keys hashed, shown once

Programmatic access uses per-account keys stored only as a SHA-256 hash with a short prefix. The full key is shown once, at creation, and never again.

Nothing sensitive reaches the logs

A fail-safe filter strips authorization headers, tokens, secrets, credentials, and raw provider responses before anything is written to a log.

Preview-first, with no delete path

New accounts preview every planned change before anything is written. Live writes go only to your own Hiya account, and the engine has no delete path to it by design.

Read-only in. Compared in CIDSync. Synchronized out.

CIDSync reads the limited phone-number data needed for branded-caller-ID sync, compares it with registry state, and writes only the difference, to Hiya Connect and nowhere else.

For ServiceTitan marketplace review

Aligned to certification expectations without overclaiming certification.

Documented data flows

CIDSync documents what it reads, what it stores, what it writes, and which systems receive data: ServiceTitan as the source, CIDSync as the review layer, Hiya as the branded-caller registry, and Stripe/Supabase/Cloudflare as operational sub-processors.

Least-privilege, approved connections

Customers connect with per-tenant credentials issued inside ServiceTitan. Access is read-only and least-privilege, and our setup steers you to approved connection paths.

Recertification-ready controls

The product keeps explicit controls for sandbox/test versus production environments, dry-run validation, record-level sync results, masked logs, and supportable audit history so certification reviews can be repeated.

No SOC 2 claim

CIDSync does not currently claim SOC 2 Type I, SOC 2 Type II, ISO 27001, or PCI certification. Instead, we publish practical controls and will answer security questionnaires while the program matures.

What CIDSync accesses

  • Active campaign or hosted business phone numbers in supported source systems.
  • Source labels, identifiers, and metadata needed to match numbers to approved brands.
  • Hiya Connect registration state and sync results for those numbers.
  • Account email, tenant settings, connection fingerprints, and operational audit history.

What CIDSync does not access

  • Call recordings, call transcripts, SMS content, customer notes, or job details.
  • Payment, payroll, accounting, invoice, estimate, or dispatch-board data.
  • Write access to source systems such as ServiceTitan or Housecall Pro.
  • Plaintext credentials after save; secrets are encrypted and never re-displayed.

Infrastructure controls

Cloud-native hosting

Application hosting runs on Cloudflare; database and auth are handled by Supabase.

Encryption

HTTPS/TLS in transit. Provider credentials are encrypted with AES-GCM before storage.

Tenant isolation

Postgres Row-Level Security limits customer-visible records to the tenant owner.

Operational controls

Auditability

Sync runs record mode, source, planned counts, applied counts, statuses, and timestamps.

Secret hygiene

Authorization headers, tokens, client secrets, and raw provider responses are not logged.

Fail-safe changes

New connections start dry-run; live writes require explicit enablement and can be disconnected.

Controls summary

Sub-processors, keys, and breach commitments

Sub-processors

Customer data is processed by Cloudflare (application hosting and edge network), Supabase on AWS us-east-1 (database and authentication), and Stripe (payments, invoices, and card storage). Company-logo images in the dashboard are fetched in your browser from Brandfetch and Logo.dev using your email domain only, with no customer records sent. Operational logging (Better Stack) and email delivery (Resend) are integrated but not currently enabled in production. We add to this list before a new sub-processor touches customer data, and this page is the record.

Key management

Provider credentials are sealed in versioned AES-256-GCM envelopes bound to their exact tenant, provider, and environment, so a copied ciphertext fails authentication anywhere else. Only the sync runtime can decrypt; no dashboard, log, or staff screen can render a stored secret (fingerprints only). Key rotation follows a documented, versioned procedure: envelopes record their key version and fail loudly rather than silently on a rotation gap.

Breach notification

We commit to notifying affected customers within 72 hours of confirming a breach involving their data, and we offer a Data Processing Agreement on request at billing@cidsync.com.

Retention & offboarding

On cancellation: syncing stops; nothing is removed from your Hiya account (the engine has no delete path to it by design); your sync history remains exportable as CSV for 60 days; stored credentials are deleted within 30 days, or immediately on request. An expired trial counts as a cancellation for deletion purposes.

Practical controls today. Formal audit later.

CIDSync is not SOC 2 certified today. For marketplace review and security questionnaires, we provide this page, our privacy policy, a data-flow summary, a sub-processor list, and direct answers on encryption, access control, incident response, retention, and deletion. We won’t claim a third-party audit until one exists.

Report a suspected vulnerability or incident to security@cidsync.com. We acknowledge within one business day and share a resolution timeline within five business days of triage.

CIDSync is an independent product and is not affiliated with, endorsed by, or sponsored by ServiceTitan, Housecall Pro, Hiya, or other named vendors.

Need the security packet?

We can provide data-flow detail, integration-scope notes, and questionnaire responses for ServiceTitan marketplace review or customer vendor review.