Security posture for early-access evaluation.
Solar1 is expected to handle job cost records, financial data, employee information, and customer records for solar installation businesses. This page explains how we frame security review before teams bring live operational data into the platform.
Early-access review
Security scoped before rollout
TLS/HTTPS
Production transport expectation
Backup planning
Retention agreed before import
SOC 2 roadmap
Not yet certified
Privacy review
Data terms confirmed as needed
No public SLA
Availability terms set in agreement
Security architecture
How Solar1 protects your data.
Data encryption
Encryption in transit
Production traffic is expected to run over HTTPS/TLS. Exact controls are reviewed during implementation planning.
Encryption at rest
Storage and backup encryption are part of the early-access security review before operational data is imported.
Sensitive fields
Financial, employee, and customer records are treated as sensitive data. Field-level handling is scoped with each rollout.
Access controls
Role-based access model
Solar1 is designed around role-aware workflows so field, finance, sales, and admin work can be separated.
Account security
MFA and SSO requirements are discussed during implementation planning instead of promised as universal defaults.
Least-privilege review
Access requirements are scoped before importing live operational data.
Support access
Support and implementation access should be explicit, limited, and reviewable. Exact process is documented in the rollout agreement.
Infrastructure
Hosting review
Hosting architecture is reviewed as part of early-access onboarding so data residency, isolation, and backup needs are explicit.
Availability terms
Availability commitments are not public self-serve guarantees. They are agreed in the customer rollout terms.
Backups and recovery
Backup frequency, retention, and recovery expectations are documented before production data migration.
Network controls
Network and administrative access controls are reviewed before go-live for teams handling financial or employee records.
Testing & monitoring
Security testing roadmap
Third-party testing and formal reports are part of the security roadmap, not a completed public certification claim.
Dependency review
Application dependencies and known CVEs are reviewed as part of the build and release process.
Monitoring plan
Operational monitoring expectations are set during rollout based on the data and workflows a team brings into Solar1.
Audit trail design
Audit logging is treated as a core requirement for financial and operational workflows. Retention terms are agreed before go-live.
Compliance
SOC 2
Solar1 is not yet SOC 2 certified. Formal compliance work is on the roadmap.
Privacy review
Privacy requirements are reviewed during rollout when teams bring customer, employee, or financial records into the platform.
Data agreements
Processing terms and data handling requirements are documented in the early-access agreement where needed.
Incident response
If something goes wrong, here is what happens.
Detection
Monitoring or a report identifies unusual activity
Containment
Affected access or systems are limited while the issue is reviewed
Assessment
Scope of impact determined — what data, which customers, how long
Notification
Affected customers are notified under the agreed legal and rollout terms
Remediation
Root cause addressed. Patch or configuration change deployed
Post-incident review
Follow-up review captures what changed and what still needs work
Responsible disclosure
If you discover a security vulnerability in Solar1, please report it to security@solar1erp.com. Include a description of the vulnerability, steps to reproduce, and the potential impact.
We will review the report, follow up with clarifying questions when needed, and coordinate next steps based on severity and impact.
Solar1 does not currently offer a bug bounty program. We evaluate each report individually and may offer recognition for significant findings.
For security questionnaires, contact security@solar1erp.com.