Authentication
Users log in with protected credentials and authenticated API routes require a valid session token.

Security and trust
OpsFlow Management is designed around company-scoped records, password hashing, admin-only audit logs, subscription access control and production HTTPS configuration.
Controls
Users log in with protected credentials and authenticated API routes require a valid session token.
Customers, invoices, quotes, stock, calendar events and job sheets are linked to the current company.
Admins can review important changes across calendar, finance, inventory, CRM, users and company settings.
Use HTTPS, strong JWT secrets, configured origins, Stripe webhooks, backups and email provider controls.
OpsFlow is configured for HTTPS, strong secrets, allowed origins, Stripe webhooks, focused rate limits, audit logging and protected environment variables. Keep database backups, 2FA, dependency updates and access reviews running before accepting real customers.
Admins can export customers, stock, invoices and quotes to CSV, giving each company a practical backup and reporting route.