Legal
Security
Effective 15 September 2026
This website
svcproof.com is a brochure. It has no login, no database, no forms and no third-party code. Every request is served over HTTPS, HTTP requests are redirected to it, and a Content Security Policy restricts the page to resources from this server alone — scripts, styles and fonts are all served from here, so no outside service is in a position to see your visit or inject anything into the page. The only thing recorded is a page-view line described in our Privacy Policy.
There is nothing on this site to break into. We mention it because a security page that overstates what it protects is worse than none.
The ServiceProof application
ServiceProof is a different system, and the questions that matter about it are real ones: it reads and writes a contractor’s live dESCO ESC database. A few principles we hold to:
- Your ESC stays yours. ServiceProof works against the database you already run. We do not take a copy of your business and keep it somewhere else as the price of using the app.
- The connection is outbound. Where we connect to an on-premise ESC, the link is established from inside your network outward. There is no inbound port to open and nothing of yours exposed to the internet to make the app work.
- Least access. The app reads the data a technician needs to do the job in front of them, and writes what that job produces. Payroll rates, costs and personal records that are stored on the same rows stay on the server.
- Who can do what is your decision. You tell us which people may create work; everyone else gets the app without those buttons.
If you are evaluating ServiceProof and need detail — how hosting is configured, how credentials are held, what an integration touches — ask and we will answer specifically rather than pointing you at a page like this one. Write to security@svcproof.com or call 717-808-0988.
Reporting a vulnerability
If you believe you have found a security issue in this site, the ServiceProof app or any ServiceProof integration, please tell us privately first — write to security@svcproof.com. Our Vulnerability Disclosure Policy sets out how to report it, what we will do with it and what testing we ask you not to perform.