Legal

Security

Last updated: October 8, 2026

The practices we use to protect the information you and your clients put into Porchlight.

Our approach

Pet care businesses trust Porchlight with client contact details, home access information and pet records, so we build with that in mind. This page describes the practices we use today. We are a small company, we do not hold independent security certifications such as SOC 2, and no service is free of risk. We would rather say plainly what we do than overstate it.

Encryption

  • All traffic between your browser or phone and Porchlight uses TLS (HTTPS). We send security headers that tell browsers to avoid mixed content and framing.
  • Our hosting and database providers encrypt stored data at rest.
  • Access instructions (such as lockbox codes) and alarm codes get a second layer: we encrypt those fields with AES-256-GCM before they are saved, using a key kept outside the database.
  • Passwords are never stored in readable form. They are salted and hashed.

Keeping each business separate

  • Each business's data is separated in the database with row-level security rules, so a signed-in user can only reach rows that belong to their own company and role.
  • Roles limit what staff can see and do. Sitters see only the visits and information they need.
  • Photos and videos are served only to people who are allowed to see the visit or pet they belong to.
  • We test these separations in our automated tests.

Sign-in and sessions

  • Sessions use cookies that page scripts cannot read (HttpOnly) and that are sent only over HTTPS.
  • Attempts to sign in, sign up, accept an invitation or set a password are throttled to slow down guessing. Error messages do not reveal whether an account exists.
  • Password reset links are single use and expire.

Audit log

Changes to money, schedules and home access information are written to an append-only audit log that records who made the change and when. The database blocks edits and deletions of those entries.

Payments

Card and bank details are entered into forms hosted by Stripe and are held by Stripe. Porchlight never stores full card numbers. Payment events from Stripe are verified by signature before we act on them.

Webhooks and API

Outgoing webhooks are signed with a secret unique to each endpoint so you can verify they came from us (see the developer page). We refuse to deliver webhooks to private or internal network addresses. API keys are scoped to a company.

Application protections

We use a content security policy and related browser protections, restrict where forms can send data, and keep the field app's camera and location permissions limited to the app itself. Dependencies are managed with a locked set of versions.

Backups and availability

Our database provider takes backups of the database. You can also export all your data yourself at any time, which we recommend as your own copy. The field app works offline and saves visit records on the device until a signal returns. We do not promise a specific uptime. See the Terms.

Your part

Use a strong, unique password. Add only staff who need access and remove them when they leave. Limit who can see home access information. Do not paste codes or card numbers into notes that do not need them.

Reporting a security issue

If you think you have found a vulnerability, please email hello@porchlight.pet with the details. Please give us a reasonable chance to fix it before you share it, and do not access other people's data or disrupt the service. We will not take action against good-faith research that follows these rules. If you believe your account is affected by an incident, email us right away.