Security & IT

Industrial trust starts with clear boundaries.

Turnover uses authenticated access, program authorization, role-based permissions, and configuration-specific controls. We describe the controls and architecture we actually use rather than claiming certifications that have not been established.

Authenticated user accessProgram-level authorizationCustomer-controlled administrative roles
Turnover business controls
TRUST & ACCESS
Customer dataCustomer-owned operational information
CUSTOMER
Program accessAuthenticated and authorized users
CONTROLLED
Shared KnowledgeSeparate paid add-on; contribution opt-in
OPTIONAL
Access controls

Give the right people the right path.

Turnover combines account authentication with program authorization and role-specific workflows.

AUTH

Authenticated accounts

Users sign in through approved account authentication before entering an authorized Turnover program.

PROGRAM

Program authorization

Program access is mapped to authorized users, with supported email, role, and program controls.

ADMIN

Local administration

Customer-designated Local Admins manage supported access, permissions, roles, and program configuration for their organization.

Limited access

External contributors do not need normal internal access.

Where configured, approved third-party contributors can use a limited workspace for assigned submissions without receiving normal access to protected internal modules.

  • Configured submission and closeout workflows
  • Internal review and clarification paths
  • Reviewer authorization kept separate from contributor access
  • Program modules and capabilities controlled by configuration and permissions

Access model

Internal authorized userAssigned program and role access
APPROVED
Local AdminSupported administrative controls
CONTROL
External contributorLimited configured workspace
LIMITED
Architecture

Current Turnover programs use defined cloud and data authorities.

Depending on program configuration and feature use, Turnover uses SQL services, Firebase/Firestore services, Realtime Database, Firebase Storage, and Turnover Login. Exact data paths vary by feature and deployment.

DATA

Operational and historical data

SQL and Firebase/Firestore services are used for different operational, configuration, and historical authorities within the product architecture.

FILES

Files and supporting content

Configured file and image workflows may use Firebase Storage and other approved service infrastructure.

ACCESS

Authentication and authorization

Turnover Login and program-level access mapping control entry to authorized programs, with role and permission behavior inside the application.

Data boundaries

Customer operational data stays customer data.

Customer retains ownership of Customer Data. Turnover processes it to provide and support the service and does not expose identifiable Customer operational content to other customers by default.

OWNERSHIP

Customer ownership

Customer Data does not become Turnover intellectual property merely because it is stored or processed in Turnover.

SHARED

Shared Knowledge is separate

Turnover Shared Knowledge may be a paid add-on. Contribution is off by default and requires separate administrator opt-in.

EXIT

Export and retention

Standard self-service policy provides a 30-day post-termination retrieval window, followed by active-system deletion and backup aging as described in the Terms.

Shared responsibility

Security still depends on customer choices.

Customers should protect credentials, use unique accounts, remove access when roles change, review administrator assignments, secure endpoints, and decide what information is appropriate for their configured program.

No absolute-security claim. No internet-connected software can guarantee absolute security. Configuration-specific requirements, backup expectations, retention needs, logging, integrations, data-processing terms, and compliance obligations should be reviewed before deployment.
Industrial boundary

Turnover supports the work. It does not replace safety systems.

Turnover is an information, workflow, continuity, and knowledge platform. It is not an emergency dispatch system, machine-control system, protective device, or safety instrumented system.

  • Keep required emergency and safety systems independent
  • Follow applicable procedures, regulatory duties, and qualified professional judgment
  • Do not rely on a Turnover notification as a substitute for required life-safety or machine-safety controls

Security contact

Report a concernCONTACT

Send suspected security incidents, unauthorized access, or privacy concerns to contactus@turnoverllc.com.

IT reviewAVAILABLE

Bring configuration-specific questions about access, data paths, retention, integrations, or deployment requirements.

Trust review

Need to review Turnover with IT, security, or procurement?

We would rather answer the real architecture and control questions than make a certification claim we cannot support.