Security & reliability

Enterprise-grade reliability.
Your data, walled off and safe.

When your warranty program runs on Cascade Connect, it stands on the same class of cloud infrastructure that runs modern banks and national SaaS platforms. Homeowners reach you, claims keep moving, and your records stay safe and separate — around the clock. Here's exactly how, in plain terms your IT or security team can check.

Reliability & data protection

What you can count on

Four commitments behind every claim your team works and every photo a homeowner uploads.

Your data is never lost

Every record and photo is continuously replicated across multiple data centers, with point-in-time recovery to any moment in the last 30 days. A hardware failure or a mistaken deletion is recoverable — your warranty history is permanent.

Walled off and private

Your homeowners, claims, and documents are isolated to your company alone. Every request passes a default-deny security check, data is encrypted in transit, and platform access is logged — so your book stays yours.

Always on by design

The platform runs on globally distributed, auto-scaling infrastructure and is engineered so a hiccup in any one part doesn't take your operation offline. Busy season or quiet week, it keeps up.

Watched around the clock

Automated monitoring watches every part of the system in real time, so issues are caught and addressed fast — often before anyone notices. Reliability is measured continuously, not left to chance.

Reliability by the numbers

The infrastructure posture underneath the platform — defensible figures, not marketing rounding.

99.95%
Database availability target
11×9s
Data durability rating
30-day
Point-in-time recovery
256-bit
Encryption in transit
24/7
Automated monitoring

Availability targets and specific service-level commitments are defined in your service agreement; figures reflect the platform's underlying infrastructure.

Tenant data isolation

How your data stays yours

Cascade Connect isolates every builder at the application layer, with a single mandatory, default-deny authorization gate in front of every read and write — enforced server-side on infrastructure a browser can never bypass. It's the same machinery that lets a warranty management company run many builders under one roof with zero bleed-through.

One default-deny gate

Every read and write is authorized against a single, mandatory gate that resolves your company's scope from the database — never from anything a browser sends. Unknown or out-of-scope requests are denied by default.

The browser never touches the database

There is no database connection or secret in any browser. Every data path runs through a server that independently authenticates and authorizes each request — there is no "trusted frontend" shortcut.

Keyed to your company

Homeowners, claims, messages, texts, calls, and documents are all keyed to your builder group. Cross-company access attempts are refused and logged, and our own operations staff cannot see a licensed tenant's data.

Even notifications are scoped

Email, SMS, and IQ phone intake are gated the same way. A notification about your tenant only ever reaches your people — on your own numbers and inboxes, never mixed with another builder.

Verified continuously

The full access matrix — owner, staff, your admins, and forged requests — is exercised by an automated test harness before and after any change, and every scope decision is monitored in production telemetry.

Encrypted, parameterized, audited

Data is encrypted in transit, every query is parameterized (no raw string SQL), and identity is verified server-side on every request from a signed token — re-checked against your records, not trusted from the client.

IQ & your data

The intelligence layer gets the same isolation

IQ — the patent-pending claims engine inside Cascade Connect — works only within your walls. What it reads, what it drafts, and what it learns from your team are scoped to your company, under the same default-deny gate as everything else.

Grounded in your own warranty

IQ drafts determinations from the warranty plan assigned to that specific home — your documents, quoted by section. It does not improvise from a generic idea of what warranties usually say.

What it learns stays yours

When your team edits a determination, IQ learns your way of making the call — and that learning is stored privately to your company. Another company's edits never shape your output, and yours never shape theirs.

A person approves every send

IQ drafts; it does not decide. Nothing reaches a homeowner or a subcontractor until someone on the team has reviewed it and clicked send — the human check is built into the pipeline, not bolted on.

Straight about how it's built

No hand-waving

The parts a good security reviewer will ask about — answered up front.

Shared infrastructure, row-level isolation

Builders share one hardened database and application; separation is enforced by the authorization layer described above — a single default-deny gate on every request — not by hoping a query remembers a filter.

Support access is the exception — and it's logged

For support, the platform owner can enter a licensed builder's workspace. When that happens it's deliberate, reason-stamped, and recorded in an access log the builder's own admins can review — so oversight isn't a matter of trust, it's a matter of record.

Proven, not asserted

The isolation model is exercised by an automated test harness against real access patterns before and after every change to the authorization layer, and cross-company attempts are denied and surfaced in monitoring — so a regression shows up immediately, not after an incident.

Questions from your IT or security team?

We're happy to walk them through the architecture, the isolation model, and what we commit to in writing. Bring the tough questions.

Get in touch