Security
Last updated: May 15, 2026
Security is built into how GabeWorks operates. The following outlines the practices we follow to protect the Quote Recovery Portal, client accounts, estimate data, and your customers' data.
Account Access
- Portal accounts and any client systems we touch remain owned and controlled by the client.
- Access is granted via least-privilege roles and revoked immediately upon engagement end.
- Multi-factor authentication is required on every account we touch.
Credential Handling
- API keys, tokens, and passwords are stored in an encrypted password manager — never in plaintext.
- Credentials are never shared over email, SMS, or chat.
- Credentials are rotated when staff or contractor access changes.
Data Protection
- All connections to the portal and client systems use TLS/HTTPS.
- Portal data is separated per client account and access is enforced at the database level.
- Estimate, quote, and customer data is processed only to provide the portal and related services.
- We do not export, sell, or repurpose client customer data.
Infrastructure
The portal is deployed on reputable, SOC 2-compliant providers (such as Cloudflare and our managed database and email infrastructure providers). We rely on their hardened infrastructure for network, physical, and platform security.
Monitoring
The portal is monitored continuously. Failures and anomalies trigger automatic alerts so issues are addressed before they impact your business.
Incident Response
If a security incident affects a client account or data we process, we will notify the affected client promptly with a description of what happened, the data involved, and remediation steps.
Reporting a Vulnerability
Found a security issue? Please email gabe@gabeworks.co with details. We appreciate responsible disclosure and will respond as quickly as possible.
