Security & IT

Industrial trust starts with clear boundaries.

Turnover is designed around authenticated Program access, customer-controlled administration, scoped permissions, bounded intelligent retrieval, controlled exports, and deliberate external-participant workflows. We describe the controls we actually use and do not claim certifications that have not been established.

Customer Data remains customer dataLeroy works inside authorized evidence boundariesExternal participation does not equal Program access
Trust boundaries
TURNOVER CONTROL MODEL
Customer DataCUSTOMER

Customer-owned operational, technical, form, file, and work information.

Leroy + TurnBaseSCOPED

Authorized evidence only. No silent AI commit or export authority.

External participationBOUNDED

Assigned workflow or tokenized form path, not normal Program access.

Access and administration

Give the right people the right path.

Turnover separates account authentication, Program authorization, Local Admin responsibility, and feature-specific permissions so one access decision does not have to open every part of the system.

AUTH

Authenticated Program users

Normal internal users sign in through approved authentication and must be authorized for the target Turnover Program before they can work inside it.

ADMIN

Customer Local Admin control

Customer-designated Local Admins manage supported Program access, roles, Work Groups, page visibility, and other configuration controls for their organization.

SCOPE

Feature-specific boundaries

Reviewer authority, Work Group and Persona scope, page access, export permissions, and other specialized controls remain separate from basic Program entry.

Leroy + TurnBase

Connected intelligence should not become a permission shortcut.

Leroy is Turnover's Program Aide. TurnBase is a structured, permission-aware and freshness-aware knowledge repository. Their current design keeps retrieval tied to authorized scope and source identity.

  • Leroy prefers exact Turnover evidence and exact source identity
  • Connected intelligence remains read-only unless an existing Turnover workflow explicitly owns a commit
  • TurnBase knowledge is bounded by Program, Work Group and Persona authority
  • TurnBase mass export is a separate Program control, disabled by default
  • Enabling export does not broaden what the signed-in user is allowed to read

AI authority model

RetrieveAUTHORIZED

Use the smallest relevant evidence set the user is permitted to access.

ExplainSOURCE AWARE

Keep record, package, revision, scope, and freshness identity available where the source supports it.

ChangeHUMAN WORKFLOW

An AI response does not silently create, verify, delete, export, approve, or overwrite authoritative Program data.

External participation

Outside participation can be useful without opening the Program.

Turnover supports more than one limited outside-workflow pattern. The important rule is that an external participant receives the path needed for the assigned work, not normal access to unrelated Program data.

FORM LINK

Tokenized external forms

Where a company template allows external participation, Turnover can issue a high-entropy tokenized form link with expiration, revocation, replay protection, rate limits, server-side validation, and private submission storage.

RETURN

Internal review stays internal

The external participant completes the assigned form. The returned submission is synchronized back into the controlled form for internal review and any configured approval chain.

CONTRIBUTOR

Limited contributor workflows

Where configured, approved contractors or specialists may use a limited contributor workspace for assigned submissions without receiving normal access to protected internal modules.

External AI workflows

Export a bounded task, not the keys to the operation.

Some Turnover workflows can deliberately package a schema or authorized data set for use with an external AI. Those workflows are designed around explicit export, human review, and controlled import instead of giving an external model unrestricted live Program authority.

  • Safety Form AI kits describe the allowed template schema and instruct the model not to invent company policy
  • Inventory AI/Data workflows can return proposed structured items for authorized review rather than writing live stock directly
  • A returned AI result must pass through the applicable Turnover review/import workflow
  • If a Customer sends exported data to a third-party AI service, that third party's terms and data handling also matter

BOUNDARY

Turnover ProgramCONTROLLED

Authenticated users, permissions, authoritative records, and customer configuration remain inside Turnover.

Explicit exportBOUNDED

Only the selected schema or authorized package is prepared for the outside task.

Review before useREQUIRED

Proposed content comes back through a human-controlled workflow before it becomes live Program data.

Architecture

Current Turnover Programs use defined cloud and data authorities.

Depending on Program configuration and feature use, Turnover uses SQL services, Firebase and Firestore services, Firebase Storage, Realtime Database, Turnover Login, and Turnover-controlled PHP service endpoints. Exact data paths vary by feature and deployment.

DATA

Operational and historical authorities

SQL and Firebase-family services serve different operational, configuration, working-state, and durable-history responsibilities inside the product.

FILES

Files and supporting content

Configured file, image, profile-photo, and private external-form workflows use controlled storage paths appropriate to the feature. Exact storage requirements can be reviewed for a deployment.

TRANSIT

Protected web connections

Turnover is served over HTTPS. Customers should also secure endpoints, browsers, credentials, and local networks used to access the service.

Configuration-specific review matters. Turnover does not promise that every Program uses every listed service in the same way. For procurement or IT review, ask for the data-flow and control details for the deployment being considered.
Customer Data boundaries

Customer operational information stays Customer Data.

Customer retains ownership of Customer Data. Turnover processes it to provide, secure, support, and improve the service for that Customer and does not expose identifiable Customer operational content to other customers by default.

OWNERSHIP

Customer ownership

Operational records, technical content, files, forms, and other Customer-submitted content do not become Turnover intellectual property merely because Turnover stores or processes them.

SHARED

Shared Knowledge is separate

Turnover Shared Knowledge may be offered as a paid add-on. Cross-customer contribution is off by default and requires separate affirmative administrator opt-in.

SERVICE PROVIDERS

Providers have defined roles

Hosting, authentication, database, storage, communications, payment, security, and configured model-processing providers may process information only as needed for their permitted service role.

Export, retention, and exit

A customer should know what happens when service ends.

Unless a different written agreement applies, the standard self-service policy provides a 30-day post-termination period to retrieve available Customer Data. After that window, active-system deletion may proceed, while protected backup remnants may age out for up to 90 days or remain longer where law, security, dispute preservation, or a written agreement requires it.

  • Normal in-product and feature-specific exports remain subject to permissions and available product controls
  • TurnBase mass export is separately controlled and durably audited
  • Backups are not intended to function as an ordinary post-termination customer archive

Standard lifecycle

Active serviceAVAILABLE

Authorized users work with Customer Data under the configured Program permissions.

30-day retrieval windowRETRIEVE

Available Customer Data can be retrieved or requested after termination unless a different agreement applies.

Active deletion + backup agingLIFECYCLE

Active-system deletion follows the retrieval window. Protected backup remnants may persist temporarily under the published policy.

Industrial boundary

Turnover supports industrial work. It does not replace safety systems or qualified judgment.

Turnover can help document safety concerns, controlled forms, approvals, work history, and related information. It is not an emergency dispatch system, machine-control system, protective device, or safety instrumented system.

01

Keep required systems independent

Do not use a Turnover notification, form, or AI response as a substitute for required life-safety, machine-safety, emergency, or protective systems.

02

Company procedures still control

Customers remain responsible for their procedures, permits, regulatory duties, training, approvals, and safe operation of facilities and equipment.

03

Human review still matters

AI-assisted explanations, form drafts, and proposed structured data should be reviewed by qualified people before they are relied on for safety, engineering, quality, or compliance decisions.

Shared responsibility

Security still depends on customer choices.

Customers should protect credentials, use unique accounts, remove access when roles change, review administrator assignments, secure endpoints, and decide what information is appropriate for their configured Program.

No absolute-security or certification claim. No internet-connected software can guarantee absolute security. Turnover has not represented SOC 2, ISO 27001, or another certification unless Turnover expressly provides current evidence of that certification. Configuration-specific logging, backup, retention, model-processing, integration, data-processing, and compliance requirements should be reviewed before deployment.
Trust review

Need to review Turnover with IT, security, legal, or procurement?

Ask for the real architecture, permissions, AI boundary, retention, and data-flow answers for the Program you are considering. Security concerns can also be reported to contactus@turnoverllc.com.