Security
Your shop's data is the business. We treat it that way.
Customer lists, repair history, money, BenchKey holds the record of everything your shop does. Here is exactly how it is protected, in plain English, because "trust us" is not an answer a shop owner should accept.
One shop, one database
BenchKey gives every shop its own isolated database. Your tickets, customers, and money are structurally separated from everyone else’s, isolation is the architecture, not a query clause.
Card data never touches us
Payments run through Square and Affirm. Card numbers go from your customer to the processor, full stop, BenchKey stores the record of the payment, never the card. That keeps the highest-risk data in PCI-audited hands.
Sign-in handled by a dedicated auth provider
Authentication runs on Clerk, a provider whose entire business is login security: hardened session management, modern password handling, and multi-factor authentication support, instead of a homegrown login bolted to the side.
Roles that mean something
Admins see everything; techs see their work. Pricing, margins, reports, settings, and payroll live behind admin permissions enforced on the server, a curious counter login cannot wander into the books.
Signed links, not guessable URLs
Customer portal pages, estimate approvals, and tracking links all use long signed tokens. Expired, tampered, or cross-ticket links get rejected, and those rejections are part of our automated test suite.
Evidence-grade records
Activity on a ticket is recorded as it happens, and the case file export is hashed with SHA-256 at generation, so you can prove a document was not altered after the fact. Your records are built to stand up when it matters.
Financial integrity
Money that can't be quietly rewritten
BenchKey records money the way accountants have since paper books: entries are added, never altered. Every payment, deposit, refund, and chargeback is written to an append-only ledger in exact cents, and a correction is a new reversing entry that sits next to the original, not an edit on top of it. There is no edit button on money history, for anyone, at any permission level, which protects you from the rare bad hire and clears the honest ones the day the drawer counts short.
- → Payments can't be edited or deleted, corrections are reversing entries
- → A paid invoice can't be voided until the refund is on the record
- → Balances and reports are derived from the ledger, never typed over it
- → Exact integer cents, no floating-point rounding in your books
The everyday discipline
Security is a habit, not a page
BenchKey runs the real customers and real money of MDRepairs, the working data recovery company it was built inside, every single day. The protections below are not compliance theater; they are how we keep our own business safe, applied to yours.
Encrypted in transit
All traffic runs over HTTPS/TLS. The app, the portal, the widget, and the API speak nothing else.
Encrypted at rest
Data lives on encrypted cloud infrastructure in the United States, disks and backups included.
Backups we actually restore
Backups run automatically, are integrity-checked, and get restore-drilled monthly against a documented disaster-recovery runbook. A backup that does not restore is not a backup, so we restore ours on purpose, before we ever need to.
Rate limiting & abuse protection
Per-IP rate limits on sensitive endpoints, Cloudflare Turnstile bot-checks on public forms, honeypots on the widget, and an allowlist of domains permitted to embed it.
Webhook signature verification
Inbound events from phone and payment providers are HMAC-verified, forged events are dropped, not processed.
Hardened by routine audits
We run adversarial audits against our own product, tenant isolation probes, payment-flow audits, dependency scans, and ship the fixes before features. No outside firm has audited us yet; when one does, the report will be linked here.
Messaging compliance built in
STOP suppressions are automatic and permanent, marketing email carries one-click unsubscribe, and SMS consent is collected and recorded where rules require it.
Least-drama incident posture
Fail-closed defaults: when something is wrong, the system denies access rather than guessing. Boring is the goal.
Your customers’ privacy
GDPR-grade data tools, built in
A repair shop holds names, phone numbers, device contents, and payment history, real personal data with real obligations. BenchKey ships the tools that make honoring those obligations a task, not a project.
One-click workspace export
Owners export the whole workspace, customers, tickets, invoices, messages, sixty-plus tables of it, as a checksummed archive. Sensitive material (signatures, ID photos) requires its own explicit confirmation, every export is rate-limited and logged, and exports lock while a deletion request is pending. Your data is yours, provably.
Workspace deletion, with a human in the loop
Leaving? Request deletion from Settings and a person follows up before anything is destroyed, then removal runs through a deliberately slow two-step process. No single click, yours or ours, vaporizes a business’s records.
Right-to-erasure requests, done right
When one of your customers asks to be forgotten, support runs an erasure that scrubs their personal details while keeping your financial records intact, invoices still add up after the name is gone. The tool then re-scans every table and refuses to report success until zero traces remain: erasure that certifies itself.
Consent on the record
SMS consent is captured with the exact text the customer saw, marketing consent is an explicit per-customer event log, and unsubscribes suppress permanently. When someone asks "did they agree to this?", the answer is a record, not a shrug.
Your customers feel it too
Security your customers can see
Trust is part of the product you sell. The portal your customers track repairs on uses private signed links, their approvals are recorded with signatures and timestamps, and the case file proves what happened on a repair, protections that quietly tell your customers they picked a professional shop.
- → Private, signed portal links per ticket
- → Approvals captured with name, signature, and timestamp
- → Payments through Square, the same processor they already trust
- → STOP always honored, instantly and permanently
Found something?
If you believe you have found a security issue in BenchKey, tell us directly and we will take it seriously, fast. Email support@benchkey.com with "security" in the subject line and enough detail to reproduce what you saw.
Please do not test against shops you do not own; a free trial gives you a tenant of your very own to poke at.
FAQ
Security questions
Is my shop data shared with other BenchKey customers?
No. Every shop runs in its own isolated database. There is no shared table where a query bug could leak one shop into another, isolation is structural, and every API request is gated by tenant before it touches data.
Does BenchKey store my customers’ card numbers?
No. Card payments are processed by Square (and financing by Affirm). Card numbers go directly to the processor and never touch or rest on BenchKey servers.
Is my data used to train AI models?
No. The AI assistant uses your data to answer you and configure your account, not to train models.
What happens if I leave BenchKey?
Your data is yours. Export your customers, tickets, and invoices yourself, and if you want the hosted copy gone after you cancel, email support and we delete it.
Are customer portal links guessable?
No. Portal and tracking links use long signed tokens. Tampered, expired, or cross-ticket links are rejected, we test those rejection paths the way other features test their happy paths.
How do staff permissions work?
Role-based access: admins see everything, techs see their work. Money, reports, settings, and other people’s pay sit behind admin permissions, enforced server-side, not just hidden in the interface.
Can BenchKey help with GDPR-style requests?
Yes. Owners can export the entire workspace themselves as a verified archive, request account deletion with a human follow-up, and ask support to run a certified erasure of an individual customer’s personal data, one that keeps your books reconciling while scrubbing the person. Consent and unsubscribe records are kept per customer.
Can an employee edit or delete a payment record?
No. Payments live on an append-only ledger: refunds and corrections are recorded as new reversing entries that sit next to the original, never edits to it, and there is no delete. A paid invoice can’t even be voided until the refund is on the record. If money moved, the record of it stays, at every permission level.
Put your shop on BenchKey
Set up in an afternoon. Import your customers and tickets, build your check-in flow, and send your first live status link the same day.
Beta launches in ~3 weeks · Beta invites go out in small groups
Founders pricing: the first 50 shops lock Pro at $59/mo for life · see pricing