1. Encryption
All data is encrypted in transit and at rest.
- In transit: every connection to MineBook uses HTTPS with TLS.
- At rest: databases, uploaded files and backups are encrypted on our servers.
- Passwords: stored only as salted one-way hashes. We can never see your password.
2. Access control
- Sign in with Google or with email and password.
- Access is limited by site and role. Users only see the sites they are given access to.
- Only authorised engineers can release designs, and only authorised roles can close or reopen shifts.
- MineBook staff access production data only when needed for support or security, and that access is logged.
3. Audit trail
MineBook records who created or changed each operational record and when. Records are corrected or voided with a reason instead of being silently deleted, and closed shifts keep every closure version.
4. Backups and recovery
Data is backed up regularly to encrypted storage, and restores are tested so we can recover if something goes wrong.
5. Infrastructure
MineBook runs with trusted hosting providers, with firewalls, security updates and monitoring. Companies that need full control can run MineBook Enterprise on their own servers.
6. Law and compliance
We manage data under the laws of Sri Lanka, including the Personal Data Protection Act, No. 9 of 2022 (as amended by Act No. 22 of 2025). See our Privacy policy for your rights and how to exercise them.
7. Report a security issue
If you find a vulnerability, please email security@minebook.lk with the details. Please give us reasonable time to fix it before sharing it publicly. We will not take action against people who report issues in good faith and do not access or change other users’ data.
