Security Overview
Not a warranty. This page describes high-level security practices for informational purposes. It does not create contractual commitments beyond those in the Master SaaS Terms, Data Processing Addendum, or Order Form. RetterTEK does not claim SOC 2, ISO 27001, HIPAA, or PCI certification on this page.
Contents
JAMr FIT is owned and operated by Premier TEK LLC, an Illinois limited liability company doing business as RetterTEK ("RetterTEK").
Encryption
- In transit: TLS for application and API traffic.
- At rest: Platform data is stored with encryption at rest provided by underlying infrastructure providers (including database and object storage platforms used to operate the Service).
Authentication
- Application authentication for staff users via Supabase Auth.
- Support for multi-factor authentication where offered and configured by the customer.
- Customers remain responsible for credential hygiene, deprovisioning former users, and endpoint security.
Authorization and RBAC
- Role-based access within each tenant (for example owner, admin, and staff roles).
- Database row-level security (RLS) policies used to enforce tenant-scoped access.
- Optional support-access grants that are opt-in, revocable, and audited.
Tenant Isolation
- Multi-tenant data model with tenant-scoped queries and access controls.
- Franchise / multi-location permissions are customer-configured; customers must not grant access beyond their contractual authority.
Logging and Audit
- Application audit logging for significant administrative actions.
- Consent, messaging, and certain workforce/timekeeping audit records retained for operational, evidentiary, and compliance purposes as described in the Master SaaS Terms and DPA.
Backups and Retention
- Infrastructure-provider backup and recovery capabilities are used as part of platform operations.
- After subscription end, Client Data may be available for a limited export window, then deleted or de-identified subject to lawful retention (see the DPA and Data Deletion Policy).
Infrastructure
- Application database and authentication: Supabase.
- CDN, edge hosting, and object storage: Cloudflare (including R2 for media assets).
- Additional infrastructure providers may be used where applicable; see the Subprocessor List.
Incident Response
- RetterTEK maintains processes to investigate confirmed security incidents involving unauthorized acquisition of, access to, or disclosure of Client Personal Data processed by RetterTEK.
- Where required, RetterTEK notifies the affected customer without undue delay and provides information reasonably available to evaluate notification obligations (see the DPA).
Subprocessors
Third parties that may process Client Data are listed on the Subprocessors page. Current legal documents are listed at the Legal Center.
Security inquiries: [email protected]