PITCH by Plug and Play
PITCH TRUST CENTER · REVIEWED AUGUST 2026

Your business data stays yours.

PITCH protects contractor operations, customer records, PITCH Books accounting, and PITCH Books Payroll with layered technical and operational controls. We explain what is protected, how recovery works, and where customers remain responsible—without claiming that any internet service is risk-free.

AES-256Managed database encryption at rest
TLSEncrypted database and website connections
PITRContinuous point-in-time database recovery
Tenant scopedServer-enforced workspace boundaries
Malware gatedAllowlisted, inspected document uploads
DATA PROTECTION

Where your records live and how they are protected

Production records are stored in a paid, managed PostgreSQL database. The hosting layer encrypts database storage with AES-256 and external database connections with TLS. PITCH adds its own controls around identity, authorization, documents, credentials, and audit history.

01

Your company owns its business records

PITCH does not sell contractor customer lists or use them for unrelated advertising. Workspace owners control authorized users, connected providers, exports, corrections, and verified deletion requests.

02

Every workspace is isolated

Customer, job, employee, appointment, document, purchasing, accounting, and payroll access is checked against the signed-in company on the server. Role and assignment rules further limit what each person can see or change.

03

Sensitive records receive extra protection

OAuth credentials and connector secrets use authenticated application encryption. Tax, receipt, bank-statement, vendor-tax, and payroll legal-evidence documents use separate encryption keys with controlled key-rotation support.

04

Files must pass safety gates

Upload size, file type, and file signatures are validated. Production document uploads require the malware scanner to be available, and protected downloads require current authorization.

RELIABILITY & RECOVERY

Built to detect failures, protect releases, and recover data.

Reliability is an operating process, not a slogan. PITCH combines application checks with managed infrastructure and release gates.

Database-aware health checks

The production health endpoint verifies database access, required workforce schema, and payroll legal-monitor readiness. Unhealthy instances do not pass application readiness checks.

Guarded deployments

New releases run schema, malware-scanner, workforce, and payroll preflight checks before serving users. Failed builds or unhealthy releases do not replace the currently running version.

Continuous database recovery

The paid managed database receives continuous point-in-time recovery coverage. Recovery creates an isolated database so data can be validated before application traffic is moved.

Dependency and regression gates

Every release runs the complete automated test suite, validates installed dependencies, audits pinned packages for known vulnerabilities, and compiles release-critical modules.

Clear boundary: PITCH does not promise uninterrupted availability or absolute security. Availability, recovery, and certification claims are published only after the related control has been measured or independently verified.

DEFENSE IN DEPTH

Protection at every boundary

No single control carries the whole load. PITCH combines account, application, data, browser, and operational safeguards.

Account protection

Passwords are never stored as readable text.

New passwords use salted Argon2id hashing. Sign-in and verification attempts are throttled, and email verification can add a second step.

Session protection

Access expires and can be revoked.

Signed, HTTP-only cookies use secure production settings. Sessions have idle and absolute limits; password changes and “sign out everywhere” revoke existing sessions.

Least privilege

Access follows role, assignment, and company.

Owners control seats and roles. Sales, field, production, accounting, payroll, and professional users receive scoped access rather than a shared company-wide login.

Integration secrets

Connected credentials are encrypted before storage.

OAuth tokens, mailbox credentials, and connector configuration use authenticated encryption. API keys are shown once and retained as one-way keyed digests.

Request protection

Sensitive actions are verified.

CSRF protection, signed webhook validation, tenant checks, idempotency controls, rate limits, and secure upload rules protect state-changing actions and provider callbacks.

Browser safeguards

Pages carry restrictive security headers.

Content Security Policy, clickjacking protection, MIME sniffing protection, limited browser permissions, and no-store rules protect sensitive screens.

PITCH BOOKS & PITCH BOOKS PAYROLL

Financial records are controlled, traceable, and reviewable.

Accounting and payroll data receives the same tenant protections as the CRM, with additional approval, evidence, and correction controls.

PITCH Books

  • Company-scoped general ledger and reconciliation records
  • Immutable source references, hashes, audit trails, and approval history
  • Encrypted receipt, bank, vendor-tax, and tax-evidence documents
  • Role-restricted close, reporting, banking, and professional workspaces

PITCH Books Payroll

  • Company and self-service payroll permissions are independently scoped
  • Approved time, wage, deduction, job-cost, pay-statement, and correction history remains traceable
  • Payroll legal-source changes create review gates instead of silently changing prior calculations
  • Tax workpapers require independent CPA/EA review; PITCH does not transmit returns or tax payments to government agencies
PLATFORM & REGULATORY BOUNDARIES

Minimum access, clear consent, and honest limits

Provider rules change. PITCH requests only the permissions required for enabled features and keeps the product disclosures aligned with the actual connection.

Google

Gmail connections request identity plus gmail.send to send user-authorized messages. PITCH does not read or search Gmail and follows Google API Limited Use requirements.

Microsoft

Microsoft mailbox connections use delegated identity, offline access, and Mail.Send. PITCH does not request mailbox-reading permission; users can disconnect in PITCH and revoke consent with Microsoft.

Apple & mobile

PITCH publishes accessible privacy and deletion information, uses platform permission prompts, and keeps sensitive approval and financial actions behind authenticated server authorization. App-store distribution remains subject to the store’s review and account-control rules.

IRS & payroll

Employers remain responsible for employment-tax accuracy, deposits, filings, notices, and required retention. PITCH supports controlled records and professional workpapers; an authorized CPA/EA and the employer control final filing and payment outside PITCH.

COMMON SECURITY QUESTIONS

Answers for owners evaluating PITCH

Does PITCH sell my company or customer data?

No. PITCH does not sell contractor customer lists or use them for unrelated advertising. Data is processed to deliver, secure, support, and improve the services the workspace requests.

Who at my company can see accounting or payroll records?

Access is controlled by server-enforced permissions. General accounting, company payroll, employee self-service payroll, approvals, and professional review use separate permissions. Owners and administrators can review and change authorized access.

What happens if a deployment fails?

The existing version continues serving traffic while the new version builds and proves readiness. A failed build, failed preflight, or unhealthy instance does not replace the healthy release.

Can I export or delete my data?

A verified workspace owner can request access, export, correction, or deletion. Some payroll, tax, transaction, dispute, security, legal-hold, and backup records may need to be retained for a documented period.

Is PITCH certified or guaranteed breach-proof?

No responsible provider can guarantee that. PITCH has not claimed SOC 2, ISO 27001, or another independent certification. The current controls are described here; independent assessment and additional operational assurance remain on the roadmap.

DOCUMENTATION

Review the details

Security OverviewSubprocessor RegisterPrivacy PolicyTerms of ServiceData Access & DeletionDMCA Copyright PolicySecurity contact policy
RESPONSIBLE DISCLOSURE

Found something that does not look right?

Please send the affected URL, what you observed, and safe reproduction steps. Do not access another customer’s data or disrupt service.

security@plugandplayco.com