Security

Defensive by design.

TradesMen.dev runs as a security-aware ecosystem. The apps we build, and the operations behind them, are designed to be defensive, privacy-respecting, and accountable.

Defensive posture Privacy-aware Accountable access

Private by default. Public by intent.

Internal findings, secret URLs, private logs, scanner internals, and exploit-style language stay off the public website. Where the ecosystem speaks publicly about security, it stays high-level and defensive by design.

  • Private — Internal findings and data stay internal.

  • Defensive — Public language is high-level and protective.

  • Authorized — Sensitive access is limited to accounts that need it.

Security across the ecosystem.

Six commitments that shape how the platform is built and operated.

Built to protect.

Our security model is based on defense — protecting the platform, the people who use it, and the data they trust us with. We do not publish offensive tooling, exploit details, or scanner findings on public surfaces.

Scoped to who should see it.

Each app is designed with privacy in mind. Data is collected only for the job it needs to support. Reports, analytics, messages, and operational stats are scoped to the people, teams, and tenants who are supposed to see them.

Least privilege, by default.

Access across apps is governed by platform roles, teams, and tenants. SSO, scoped permissions, approvals, and grants protect sensitive actions. Separation of duties keeps administrative access limited to accounts that need it.

Watched by Security Center.

TradesMen Security Center is the defensive monitoring and incident response hub across every app. It watches registered software apps, APIs, dependencies, infrastructure, logs, incidents, backups, and integration health — without exposing internal details to the public.

Loud inside, graceful outside.

When something goes wrong, it should be loud for the responsible platform team and graceful for everyone else. Alerts, logs, runbooks, Security Center workflows, and vendor tools help route issues quickly. Public communication stays calm and protective while issues are resolved.

Found something? Tell us.

If you believe you’ve found a security issue affecting TradesMen.dev or any TradesMen app, please report it responsibly. We’ll review it carefully and handle it safely. Please do not publish vulnerability details, scanner output, or private data publicly.

Contact us

TradesMen.dev is owned and operated by Pimentel Services Ltd.

Need to report a security concern?

Use the contact form and select the Security report topic. We’ll route it quickly.