BenchOS runs a live multi-location Apple service business every day, so security isn't a badge we bought, it's how the system is built. No vague promises below, just exactly what protects your money, your customers' data, and your Apple credentials, and how each of those is enforced.
Every table is scoped to your shop by Postgres row-level security. Another shop can't read your rows, even querying the database directly, because the boundary sits below the application, not in the interface. A UI bug can't leak what it was never allowed to load.
Payments run through your own Stripe account. Money settles straight to your bank, BenchOS never holds your funds, and card numbers go directly to Stripe, never our servers, keeping us out of the sensitive part of PCI scope by design.
Totals, tax and balances are calculated by the database from the job's line items and payments, so the app can't write a wrong number and everything reconciles to the cent. What the customer pays and what you're owed are the same figure everywhere.
Your Apple service certificate is uploaded through BenchOS and stored, isolated to your shop, on our hardened GSX gateway, the only system that talks to Apple. It authenticates your shop's GSX calls and nothing else, and no other tenant can reach it. There's no gateway for you to install or run.
Apple's labor reimbursement is tracked through a single enforced boundary in the code. A customer is never billed Apple's money, Apple's credit never inflates your revenue, and your books stay clean on both sides.
The customer portal is least-privilege: a logged-in customer can only reach their own tickets and invoices, enforced by the same database rules that isolate shops, not by hiding buttons. Staff access is role-based on top.
BenchOS is never in the middle of your money. A card payment goes to your own Stripe account and settles to your bank on Stripe's schedule.
BenchOS earns only its plan fee. On paid plans there's no platform fee on card payments at all. See pricing for the exact numbers.
The unglamorous parts matter most, so they run on proven, managed infrastructure rather than anything we hand-rolled.
No. You're the merchant of record on your own Stripe account. Funds go straight to your bank, and BenchOS is never a stop in between.
No. Isolation is enforced in the database itself, not just in the interface, so one shop's account cannot read another's data even through a direct query.
No. Card details go directly to Stripe and never touch our servers. Saved cards are held as Stripe tokens, not raw numbers.
It's uploaded through BenchOS and stored isolated to your shop on our hardened GSX gateway, the only system that talks to Apple. It authenticates your shop's GSX calls and nothing else, over a locked-down, Apple-allowlisted connection, and it's kept separate from every other tenant.
No. Your shop's data is used to run your shop. It isn't sold, and it isn't shared with other tenants.
Your data goes with you. Customers, devices and history can be exported, so there's no hostage-taking to keep you on the platform.
If your shop has a specific requirement, or you're vetting BenchOS for a multi-location move, ask us directly. You'll talk to people who run repair shops, not a ticket queue.