Data Security and Shared Responsibility.
SHIFTFM applies technical and organizational controls proportionate to the nature of the service, the data involved, and the relevant risks, including access management, customer isolation, session protection, connection security, and service continuity within the approved operating architecture.
Security Approach.
SHIFTFM applies technical and organizational controls proportionate to the nature of the service, the data it processes, and the relevant risks. The approach includes access management, customer isolation, session protection, connection security, and service-continuity practices aligned to the approved operating architecture.
Access to facilities, records, and attachments is limited according to account roles, permissions, and organization boundaries rather than blanket visibility.
Operational records and related metadata may be used to support troubleshooting, abuse review, and service protection.
Each customer’s data is managed through its assigned operating environment and access-isolation controls designed to limit cross-customer overlap and unauthorized access.
Controls are applied according to the nature of the service, the data involved, and the operational risk profile.
Files and Attachments
Authorized users may upload operational images, documents, and attachments through supported functions.
The presence of upload functionality does not mean that every file type is allowed or appropriate for processing.
For operational documents classified as sensitive within a facility, access should be limited to users whose administrator granted the necessary operational permissions.
Files remain subject to the Acceptable Use Policy, and file types, file sizes, attachment counts, or upload functionality itself may be restricted when there is a security risk or abuse concern.
Files and attachments are subject to SHIFTFM’s acceptable-use and security controls. SHIFTFM may restrict, reject, suspend processing of, or remove a file where its type, content, or behavior creates a security or operational risk or violates the applicable terms.
Security Incidents
When SHIFTFM identifies a security issue affecting service operations or customer data, it works to assess, contain, investigate, and mitigate the issue within the context of the applicable environment and legal obligations.
Technical Service Providers
Some service components depend on categories of technical providers such as hosting, infrastructure, databases, communications, backup, and related support services required to operate the service.
Need Clarification for Your Team?
Contact SHIFTFM for security, legal, or implementation clarification specific to your operating use case.