Trust & security

Plain answers about your data.

Operators running more than one store ask us the same things before they sign: where their data lives, who can see it, and what happens if something goes wrong. This is how Smoke Alarm works today. Where we have not built something, we leave it out rather than dress it up.

Last updated September 2026

Where your data lives

Smoke Alarm runs on Vercel, and its database is PostgreSQL hosted by Neon. What your team enters or connects is kept in that database: inventory, counts, findings, investigations, evidence files, audit binders, assistant conversations and the audit history.

The site and the app are served over HTTPS, and the application's connection to the database requires TLS.

Some of it is sent elsewhere on purpose, and approved corrections go to Metrc as described below. Email we send you, such as alerts, reports and invitations, goes out through our email provider, Resend. When an AI model writes an explanation or an assistant answer, the records it needs for that answer are sent to the model's provider: Anthropic, or a model reached through OpenRouter. What those providers retain is set by their own terms, and we do not make promises on their behalf.

Who can see it

Your records belong to your organisation. Access is checked on the server, in the application's code, so a customer's account reaches only the records of the organisations it belongs to. Audit Shield AI's own access is described below.

  • Owners and managers see every location in the organisation.
  • Staff work in the locations they have been given; inventory, findings, investigations and reports for other locations are not shown to them.
  • Within your team, only owners and managers can connect a location, store a key or approve a correction.

Audit Shield AI's named platform administrators can open any organisation, to set it up and to support it. The material changes they make are written to your audit history under their name, the same as your team's.

The codebase includes automated tests that try to reach one organisation's records as a person from another organisation, and expect to be refused.

Credentials and secrets

Keys you give us for Metrc and for your point of sale are encrypted with AES-256-GCM before they are written to the database. The encryption key is kept in the hosting environment's configuration, not in the database.

Once a key is stored, the app shows only its last four characters, and the audit entry for storing it records those four characters and nothing more. A stored key is decrypted on the server only to call Metrc or your point of sale with it.

Keys are entered in a secure form that posts straight to the server, not into the assistant's conversation.

  • Passwords are stored only as scrypt hashes, never in plain text.
  • Sign-in sessions are held in a cookie that page scripts cannot read, and repeated failed sign-ins from one network address are refused for a few minutes.

What the AI can and cannot do

The numbers are not AI. Reconciliation, variance, regulatory thresholds and whether a package may be sold are worked out by fixed rules in code, and a language model never computes or changes them.

AI writes the plain-language explanation after the numbers are settled. Each explanation says which model wrote it or, when no model was available, that it was written from the numbers.

The assistant looks things up as the signed-in person, with the same permissions the screens use. Anything the assistant proposes that would change data waits on a card until a person approves it. None of the assistant's tools can write to Metrc.

If a message typed to the assistant looks like it carries an API key or a password, it is refused before it is stored or sent to a model. That check is a safety net, not a promise; the secure form is the route for keys.

Writes to Metrc and your point of sale

Smoke Alarm reads from Metrc and from your point of sale. The only thing it writes to Metrc is a package adjustment, and only after a correction has been approved by a person with approval rights: an owner or manager in your organisation, or an Audit Shield AI platform administrator acting in your account. A manager cannot approve a correction they proposed themselves.

Every approved write goes through a write-operation ledger that records what was intended, who approved it, what Metrc answered, and what a read of the package showed afterwards. Before sending, the package is checked again; after sending, it is read back. If Metrc's answer never arrives, nothing is resent until a read shows whether the first attempt landed.

  • It never accepts a transfer in Metrc; that capability is switched off.
  • Connections to your point-of-sale vendor only read. Smoke Alarm writes nothing back to them.
  • During a pilot, a location or a whole organisation can run in shadow mode: every check still runs, and every write to Metrc is held.
  • It never files anything with a regulator.

The audit trail

Material actions are written to an audit history your team can read in the app. Each entry names who did what, when, and to which record.

What it covers:

  • Sign-ins and password changes.
  • Keys stored or removed, connection tests, and switches between simulated and live.
  • Investigations, recounts, evidence, corrections and every decision on them.
  • Each step of a write to Metrc, from proposal to the read-back.
  • Audit binders prepared and downloaded.
  • Changes the assistant makes after a person approves them.

The application only ever adds entries. It has no screen or feature for editing or deleting one.

It records what people do, not every page they open.

Simulated versus live data

Every location starts on a simulated connection. Until a location is switched to live, its figures come from a simulation, the app says so on screen, and the records it produces are labelled SIMULATED. The sample dispensary in the product is fictional.

A location moves to live Metrc only when live connections are switched on, Audit Shield AI's Metrc integrator key is in place, your own Metrc key is stored, and a connection test has passed in the last 24 hours. Storing a key never switches anything live on its own. A location can be switched back to the simulation at any time.

If something goes wrong

Any software can fail, and this page will not pretend otherwise. If we learn that customer data has been exposed, we will tell the affected customers promptly and honestly, including what we do not yet know.

What can be done straight away:

  • One platform switch turns off every live connection to Metrc and to point-of-sale systems at once. Stored keys stay encrypted and unused until it is turned back on.
  • A stored key can be removed from a location. The location drops back to the simulation, and the removal is written to your audit history.
  • If you think a key has been exposed, revoke it where it was issued, in Metrc or with your point-of-sale vendor, then give us the new one through the secure form.

Questions

If your IT or compliance lead has a question this page does not answer, ask us. If the honest answer is “not yet”, that is the answer you will get.