Business separation
Core records carry an organization boundary, and access is checked against the authenticated business context. One pet-care company should not be able to read another company's clients, pets, bookings, sitters, or messages.
Security and trust
Sitterly may hold access instructions, contact details, pet medical context, team identities, messages, location data, and payment records. Security is part of operating the product, not a badge on the website.
Ask a security questionHow access is handled today
The private beta has real controls and verification in place. The descriptions here are intentionally specific and do not stand in for an independent certification.
Core records carry an organization boundary, and access is checked against the authenticated business context. One pet-care company should not be able to read another company's clients, pets, bookings, sitters, or messages.
Owners, organization administrators, sitters, clients, and platform administrators have different responsibilities. Sensitive actions are checked against the person's role and relationship to the record.
Entry instructions and other sensitive home details receive stronger handling on higher-risk views and actions, including non-cacheable responses and additional assurance checks.
The application uses server-validated sessions, fails closed on confirmed membership revocation, and supports an additional authentication factor for protected accounts.
Selected sensitive actions emit audit events. The engineering workflow also includes dependency checks, secret scanning, protected build gates, and authorization and tenant-boundary tests.
Current private-beta posture
Controls, tests, and engineering gates exist today. Hardening work and production verification are still in progress, so we do not describe the program with absolute or certification-style claims.
Each pet-care business remains responsible for its own staff, devices, permissions, and handling of client information.
Report a concern
Send security questions or suspected vulnerabilities to support@sitterlysoftware.com. Do not include live client secrets, passwords, full payment data, or unnecessary personal information in the first message.