Pitline

Pitline

Security

Pitline is built so a city desk stays inside its own org, phones have to be trusted, and outside crews never get a login.

Updated September 23, 2026

Accounts and devices

Sign-in uses email and a password. New devices must pass an email one-time code before they reach the queue. Native Android and iOS apps talk to Pitline over HTTPS with the same session tokens. Those apps do not ship Stripe keys, webhook secrets, or JWT signing material.

Organization walls

Tickets, media, comments, contractors, and billing live on the city organization you belong to. Server functions check authentication and membership before they read or write that data. Unguessable record IDs are used for access checks, not email addresses.

Contractor job links

Third-party crews get a long random token in a URL. They never create a Pitline user. The token is required to see or update that job. Treat the link like a work order: do not post it on a public website.

Payments

Card data never touches Pitline servers. Checkout and the customer portal run on Stripe. Pitline holds a restricted live API key with only the billing permissions this product needs, plus a webhook signing secret. Incoming Stripe events are signature-checked before status changes.

Media and transport

Photos and short video go to encrypted file storage after client-side compression. The web app is served over HTTPS. Content-Security-Policy on the desk allows the map tiles and API endpoints it actually uses.

Retention

Canceled paid organizations are kept for 120 days so a city can reactivate, then deleted. Ask a city manager to remove a reporter or crew member sooner.

Report a problem

If you find a security issue, contact the Pitline operator through the city that invited you, and do not use a production job link or live checkout as a test harness on someone else's org.