Security and trust

Home access changes the security standard for pet-care software.

Sitterly may hold access instructions, contact details, pet medical context, team identities, messages, location data, and payment records. Security is part of operating the product, not a badge on the website.

Ask a security question

How access is handled today

Controls follow the sensitivity of the work.

The private beta has real controls and verification in place. The descriptions here are intentionally specific and do not stand in for an independent certification.

Business separation

Core records carry an organization boundary, and access is checked against the authenticated business context. One pet-care company should not be able to read another company's clients, pets, bookings, sitters, or messages.

Role-aware access

Owners, organization administrators, sitters, clients, and platform administrators have different responsibilities. Sensitive actions are checked against the person's role and relationship to the record.

Stricter handling for home access

Entry instructions and other sensitive home details receive stronger handling on higher-risk views and actions, including non-cacheable responses and additional assurance checks.

Protected sessions and identity checks

The application uses server-validated sessions, fails closed on confirmed membership revocation, and supports an additional authentication factor for protected accounts.

Traceability and automated checks

Selected sensitive actions emit audit events. The engineering workflow also includes dependency checks, secret scanning, protected build gates, and authorization and tenant-boundary tests.

Current private-beta posture

Security work continues before broad launch.

Controls, tests, and engineering gates exist today. Hardening work and production verification are still in progress, so we do not describe the program with absolute or certification-style claims.

What we do not claim today

  • Sitterly is not currently presented as SOC 2 certified.
  • We are not publishing a completed independent penetration-test report.
  • Private beta does not mean every security roadmap item has been deployed and proven in production.

Each pet-care business remains responsible for its own staff, devices, permissions, and handling of client information.

Report a concern

Contact us directly.

Send security questions or suspected vulnerabilities to support@sitterlysoftware.com. Do not include live client secrets, passwords, full payment data, or unnecessary personal information in the first message.