AT A GLANCE
Evaluate plumbing software security by checking account access, permissions, record history, data handling and recovery. Ask who can see each type of information and test staff removal. A country-specific website or a security badge alone does not establish where data is stored or which safeguards are in place.
Match access to the work
Start with the information your team holds
List customer contact details, service addresses, access notes, job descriptions, approvals and attachments. Decide which roles need each category. Some information is necessary for a field visit but should not be visible to every office user or every participating provider.
Use fictional records for initial demonstrations. Ask the vendor to show the authorized view and an account that should not have access. A policy statement is useful, but the behavior also needs verification.
Ask for specific evidence
| Area | Evidence to request |
|---|---|
| Sign-in | Supported authentication and recovery process |
| Permissions | Role-specific views demonstrated with separate accounts |
| Staff removal | Revocation of active access and owned workflows |
| History | Which changes are recorded, with what detail |
| Recovery | Backup scope, restoration process and responsible team |
| Data exit | Export format, attachments, retention and deletion process |
A log of sign-ins does not prove that every field edit is audited. Ask about the particular events your business needs, such as changed scope or altered customer contact details.
Use individual accounts and stronger sign-in controls
CISA recommends multifactor authentication for business systems. Ask which methods the proposed product supports and how lost-device recovery is handled. Use individual accounts so access can be changed without redistributing a shared password.
Run an offboarding exercise: remove a fictional staff account, check its active session and ensure its outstanding work has a new owner. Removing access should not make important job responsibility disappear.
Confirm regional and contractual requirements
For a business in the United States, ask the vendor to identify hosting locations, relevant service providers and the agreements that govern your data. A USA domain does not prove local-only storage. Requirements depend on the information and your business; resolve them with the appropriate adviser before importing sensitive records.
Keep answers dated and distinguish a current control from a planned improvement. Do not treat a generic checklist as a certification or a legal compliance assessment.
Know what Flor’s public information establishes
Read the current Flor Plumbing privacy page and discuss live operational retention, export and permission requirements before onboarding. The marketing demo contains fictional data and does not verify every requested security control for a live business account.
Ask for the controls that matter to your actual work and record any unanswered questions in the software scorecard. Do not enter private customer records, passwords or payment details in a sales enquiry.
Common questions
Does a Canadian website prove data stays in Canada?
No. Confirm hosting locations and subprocessors with the vendor. The website’s domain and currency do not establish data residency.
What should an audit trail show?
Ask which events are recorded, who performed them, when they occurred and whether the relevant before-and-after details are available. Support varies by event and product.
Bring your workflow to the demo
Explore the fictional request-to-approval journey, then discuss the capabilities your business needs.