Security

Security posture for early-access evaluation.

Solar1 is expected to handle job cost records, financial data, employee information, and customer records for solar installation businesses. This page explains how we frame security review before teams bring live operational data into the platform.

Early-access review

Security scoped before rollout

TLS/HTTPS

Production transport expectation

Backup planning

Retention agreed before import

SOC 2 roadmap

Not yet certified

Privacy review

Data terms confirmed as needed

No public SLA

Availability terms set in agreement

Security architecture

How Solar1 protects your data.

Data encryption

Encryption in transit

Production traffic is expected to run over HTTPS/TLS. Exact controls are reviewed during implementation planning.

Encryption at rest

Storage and backup encryption are part of the early-access security review before operational data is imported.

Sensitive fields

Financial, employee, and customer records are treated as sensitive data. Field-level handling is scoped with each rollout.

Access controls

Role-based access model

Solar1 is designed around role-aware workflows so field, finance, sales, and admin work can be separated.

Account security

MFA and SSO requirements are discussed during implementation planning instead of promised as universal defaults.

Least-privilege review

Access requirements are scoped before importing live operational data.

Support access

Support and implementation access should be explicit, limited, and reviewable. Exact process is documented in the rollout agreement.

Infrastructure

Hosting review

Hosting architecture is reviewed as part of early-access onboarding so data residency, isolation, and backup needs are explicit.

Availability terms

Availability commitments are not public self-serve guarantees. They are agreed in the customer rollout terms.

Backups and recovery

Backup frequency, retention, and recovery expectations are documented before production data migration.

Network controls

Network and administrative access controls are reviewed before go-live for teams handling financial or employee records.

Testing & monitoring

Security testing roadmap

Third-party testing and formal reports are part of the security roadmap, not a completed public certification claim.

Dependency review

Application dependencies and known CVEs are reviewed as part of the build and release process.

Monitoring plan

Operational monitoring expectations are set during rollout based on the data and workflows a team brings into Solar1.

Audit trail design

Audit logging is treated as a core requirement for financial and operational workflows. Retention terms are agreed before go-live.

Compliance

SOC 2

Solar1 is not yet SOC 2 certified. Formal compliance work is on the roadmap.

Privacy review

Privacy requirements are reviewed during rollout when teams bring customer, employee, or financial records into the platform.

Data agreements

Processing terms and data handling requirements are documented in the early-access agreement where needed.

Incident response

If something goes wrong, here is what happens.

1

Detection

Monitoring or a report identifies unusual activity

2

Containment

Affected access or systems are limited while the issue is reviewed

3

Assessment

Scope of impact determined — what data, which customers, how long

4

Notification

Affected customers are notified under the agreed legal and rollout terms

5

Remediation

Root cause addressed. Patch or configuration change deployed

6

Post-incident review

Follow-up review captures what changed and what still needs work

Responsible disclosure

If you discover a security vulnerability in Solar1, please report it to security@solar1erp.com. Include a description of the vulnerability, steps to reproduce, and the potential impact.

We will review the report, follow up with clarifying questions when needed, and coordinate next steps based on severity and impact.

Solar1 does not currently offer a bug bounty program. We evaluate each report individually and may offer recognition for significant findings.

For security questionnaires, contact security@solar1erp.com.