A separate store per deployment. tayr.app and each tenant site — zsrecycling.tayr.app, for example — run as their own Worker with their own Durable Object store, and different deployments cannot read each other's records at all. Inside a deployment, every record carries the account it belongs to and each API request is scoped to the signed-in user's company before anything is returned, so another customer's invoices are absent from the response rather than hidden in the interface.
Nothing sits on a server in an office. Records live in Cloudflare's Durable Object storage, which is attached to the object and, in Cloudflare's own words, "private to its unique instance and cannot be accessed by other objects." Files and photos live in R2 object storage and are served back through the Worker under the same role check as the record they belong to.
Encrypted at rest, encrypted in transit. Cloudflare encrypts all Durable Object data, including metadata, at rest using LUKS disk encryption with AES-256, and R2 objects the same way, with keys managed by Cloudflare. Traffic between your browser and the platform is TLS. Access inside the app is role-based — owner, admin, user — and enforced at the API layer, so a permission you do not hold cannot be reached by calling the endpoint directly, and sensitive actions are logged with the user and the time. More on security.
You are not locked in, and the store is recoverable. SQLite-backed Durable Objects support point-in-time recovery — Cloudflare can restore the store to any point in the past 30 days. Clients, purchase orders, receiving, inventory, invoices and compliance records export to CSV and Excel; invoices, purchase orders, receiving reports, weighmaster certificates and the CalRecycle paperwork print to PDF. On termination the agreement provides a data export, and the data stays yours.
Separate store per deployment · Requests scoped per account · TLS in transit · AES-256 at rest · Role-based access · Audit logging · PITR 30 days · Export any time