Security and privacy

Security you can explain to your clients.

How Pendira keeps your jobs, engineers and money safe, in plain words. Hosted in the EU, GDPR compliant, never sold.

Last updated 2 October 2026

Trust

Your data. Your engineers. Your margin.

Built in the Netherlands, hosted in the EU. A data processing agreement with every customer. And we never sell your data. Not to anyone.

  • Hosted in the EU

    Your jobs, files and records are hosted in the EU. Pendira is made by AGByte Labs in the Netherlands.

  • GDPR compliant

    We sign a data processing agreement with every customer, export or delete personal data on request, and keep ID documents only as long as needed.

  • We never sell your data

    Your data is never sold, rented or shared for advertising. It is used to run Pendira for you, nothing else.

  • Access by role

    Roles and 38 permissions decide who sees what. Prices, rates and margins are removed by the server for anyone without permission, not just hidden on screen.

  • Every change logged

    Every change records who, when, and the value before and after. Corrections never overwrite the original.

  • Secure sign-in

    Two-factor sign-in, on by default for new companies, and accounts lock after repeated failed attempts.

  • Engineer links with a code

    Each engineer gets a private link that expires. A 6-digit code sent to their own phone opens it, and they see only their own work.

  • Private files

    Photos, signatures and receipts are private. Links to them expire within minutes, and every upload is checked before it is kept.

  • Encrypted in transit and at rest

    Every connection uses HTTPS. Your data and files are encrypted at rest. Passwords, links and codes are stored only as one-way hashes.

Access

Money stays with people allowed to see it.

Roles and 38 permissions decide who sees prices, rates and margins. The server removes what someone may not see.

  • Two-factor sign-in on by default

  • Accounts lock after failed attempts

  • Sensitive changes ask you to confirm

See roles and permissions
The same job seen by three roles: the owner sees price, rate and margin, the coordinator not the margin, the client none of them.

Who sees the money

Same job, three views

  • OwnerPriceRateMargin
  • CoordinatorPriceRatehiddenMargin
  • ClienthiddenPricehiddenRatehiddenMargin

Your data

Hosted in the EU. Yours to take.

Your jobs, files and records are hosted in the EU. We sign a data processing agreement with every customer and export your data on request.

  • Private files, links that expire

  • Every change logged

  • A published sub-processor list

See sub-processors
The activity log of one job: who did what and when, from logging the job to a rate change.

Activity

JOB-1042

Sanne logged the job

Mon 08:12

Quote accepted, PO 77812

Mon 08:20

Daan checked in at Store 118

Thu 07:55

Rate € 65 to € 70, by Sanne

Thu 14:02

How we keep Pendira safe

This page lists our security controls in plain words, so you can answer your own clients and fill in supplier questionnaires faster. Pendira is made by AGByte Labs in the Netherlands.

Where your data lives

  • The servers that run Pendira and the database that holds your jobs, teams and records are hosted in the EU.
  • Photos, signatures, receipts and documents are kept in private storage under EU jurisdiction.
  • Every company that helps us run Pendira is named on our sub-processors page, with what it does and where.
  • Text messages and emails travel through their delivery providers. We list each provider before it carries your messages.

Who sees what

  • Five ready-made roles (Admin, Manager, Coordinator, Finance and Viewer), 38 permissions and custom roles.
  • Every request is checked against the person's permissions and the clients they may see.
  • Prices, rates and margins are removed by the server for anyone without permission, so they cannot leak through a screen or an export.
  • Nobody can give a permission they do not have. The Admin role cannot be changed, and every company always has an Admin.
  • Each company's data is kept apart. Every record carries its company, and every query is limited to it.
  • Your engineers, clients and rates are never shown to another company. Pendira is not a marketplace.

Sign-in

  • Two-factor sign-in with an authenticator app and recovery codes, required by default for new companies.
  • Five failed passwords in 15 minutes lock sign-in for that email for 15 minutes.
  • Passwords are stored only as argon2id hashes. New passwords are checked against common and leaked passwords, without the password leaving Pendira.
  • Sessions live in secure, HttpOnly cookies, never in a link.
  • Sensitive changes ask you to sign in again if your last sign-in was more than 10 minutes ago.
  • You can sign out of every device at once.
  • Sign-in, links and codes are rate limited per address.
  • Each engineer link is a long random token, stored only as a keyed hash.
  • A 6-digit code, sent only to the phone on the engineer's profile, opens the link. A code lasts 10 minutes and allows 5 tries.
  • An engineer sees only their own offers, work orders, rate and extra costs. Never your price, your client's name, other engineers or internal notes.
  • Guest links are read-only and expire after 1 to 90 days. You can revoke one at any time, and it stops working at once.
  • A guest link shows status, schedule and proof. Never prices, contact details or notes.

Files

  • Photos, signatures and receipts are private. Links to them expire within minutes.
  • Every upload is checked for its type and size. A file that does not match is deleted.
  • Uploads that are never completed are deleted after 24 hours.

Encryption

  • All traffic to Pendira uses HTTPS.
  • Your database and files are encrypted at rest.
  • Two-factor secrets are encrypted. Links, codes and session tokens are stored only as keyed hashes.
  • Request logs keep their contents encrypted and expire after 90 days.

Every change logged

  • Every change records who, when, and the value before and after.
  • The activity log is append-only. Corrections never overwrite the original.
  • Sign-ins, failed attempts, lockouts and two-factor changes are recorded as security events.
  • When our team changes something in your company, such as your plan, it shows in your activity log.

Our own access

Our team works in your data only to set up your company, keep Pendira running or help when you ask. We never sell your data, and we use it for nothing but running Pendira for you.

What we do not claim

Pendira does not hold ISO 27001, SOC 2 or any other security certification today. Our providers' certificates are theirs, not ours. We are GDPR compliant, and we sign a data processing agreement with every customer.

Report a security issue

If you find a weakness in Pendira, write to [email protected]. Please give us time to fix it before you share it. A person on our team reads every message.

FAQ

Questions, answered.

Something else on your mind? Talk to us. A person reads every message.

Talk to us

Do you hold ISO 27001 or SOC 2?

Not today. Pendira holds no security certification, and we never present a provider's certificate as our own. We describe our controls plainly on this page and answer your security questionnaire.

Can you fill in our supplier questionnaire?

Yes. Send it to [email protected] and a person on our team fills it in. We answer from the controls on this page, our data processing agreement and the sub-processor list.

Where is our data hosted?

In the EU. Your jobs, records and files are hosted in the EU, under a data processing agreement. The sub-processor list names every company that helps us run Pendira, what it does and where.

Can our client or an engineer see our margin?

No. A guest link shows your client status, schedule and proof, never prices. An engineer sees only their own work and their own rate. Inside your team, roles decide who sees prices, rates and margins.

Is Pendira a marketplace?

No. Your engineers stay yours. Pendira never shows your engineers, clients or rates to another company, and we never take a cut of anyone's pay.

Who at Pendira can see our data?

Our team works in your data only to set up your company, keep Pendira running or help when you ask. Changes we make to your company show in your activity log.

What happens if there is a breach?

We tell you without undue delay, explain what happened and which data is involved, and help you meet your own duties under the GDPR.

Can we get our data out?

Yes. Ask us and we export your data for you. When you leave, we return your data on request and then delete it, as your data processing agreement sets out.

Every job, from request to paid.

See Pendira with your own jobs in a 30 minute demo. Bring a messy week, and we will show you that week in one record.

EU based. GDPR compliant. We never sell your data.

A smiling engineer crouches with his laptop beside a server rack

Cookies, honestly

Necessary

Always on

The consent cookie itself. Nothing else.