Skip to content

Approaching: Nov 20, 2026 — HCS 2024 Deadline. Get ready →

Security, in things you can check yourself

Most security pages are a list of words an IT reviewer cannot test. This one is the opposite: every line below was measured on the running application on October 8, 2026, and every line tells you the command or the click that measures it again. Where we hold no claim, there is no paragraph — an absence is more useful to you than a sentence you would have to trust.

The headers the application serves

Read off the live response of app.hazcomfast.com on October 8, 2026. Run curl -I https://app.hazcomfast.com/ and compare.

HeaderValue servedWhat it does for you
Strict-Transport-Securitymax-age=63072000; includeSubDomainsThe browser refuses to talk to the application over plain HTTP for the next two years, subdomains included, after the first visit.
Content-Security-Policyframe-ancestors 'none'No other site can put the application in a frame, which is what a clickjacking overlay needs.
X-Frame-OptionsDENYThe same refusal, in the older header that browsers without CSP support still read.
X-Content-Type-OptionsnosniffThe browser takes our word for a file's type instead of guessing from its bytes.
Referrer-Policystrict-origin-when-cross-originA link out of the application carries our origin, never the path of the page a worker was on.
Permissions-Policycamera=(self), accelerometer=(), display-capture=(), ...The camera is allowed for the QR scanner and for inspection photos. Screen capture, motion sensors and the rest are turned off rather than left at the browser's default.

What the application does, and how you see it

Sessions you can end from the account screen

The account settings list every signed-in session with its device, its address and the time of its last activity, and each one can be revoked. The session you are using is marked so you cannot sign yourself out by accident.

Sign in on a phone and on a laptop, then revoke the phone from the laptop. The phone is signed out on its next request.

An audit log that only accepts new entries

Audit entries are written by the database when the record changes, not by an optional step in the browser that a closed tab would skip. The log itself takes inserts and refuses updates and deletions: the database raises an error rather than silently allowing a rewrite. Every action reads as plain language, in English or in Spanish, and the filter offers every action rather than a short list.

Switch the application to Spanish and open the audit log: every action reads in Spanish, with no raw codes.

"Access denied" is not the same screen as "nothing found"

When the database refuses to return audit entries your account may not read, the screen says so and offers Retry. It used to say there were no logs for the period, which is the same sentence a genuinely empty log produces. For an employer who has to produce records on request, “there is nothing” and “you may not see it” are opposite answers, and only one of them is defensible.

Ask an administrator to open the audit log from an account without the right to read it. The screen names the refusal.

Spreadsheet exports are written as text

When a cell would start with =, +, - or @, with a tab or with a carriage return, the export writes an apostrophe in front of it — the treatment OWASP recommends against formula injection in CSV files. That applies to the OSHA 300 Log, corrective actions, the chemical inventory and the audit log.

Name a test product =1+1, export your inventory to CSV, and open the file in a text editor: the cell starts with an apostrophe.

A PDF opens without calling anyone else

The viewer that draws a safety data sheet and the engine that reads text out of it are served by the application's own domain at startup, so displaying a sheet does not fetch code from a third party. The viewer is kept at or above the version that fixed its known flaw.

Open a sheet with the browser's network tab recording. Every request is to the application or to its storage.

A file link in an audit entry only opens back to us

A link saved inside an audit entry becomes clickable only when it is HTTPS and points exactly at the application or its storage. Anything else is shown as “Link not allowed” instead of being offered to the person reading the log.

There is nothing to do here, which is the point: the check runs before the link is rendered.

What a plan can never lock

One part of this belongs on a security page rather than a pricing page, because it decides what happens to a worker on a bad month. The billing lock acts on writing only. Reading a safety data sheet, the emergency screen, a container scan, a guest link, the subcontractor portal, a worker’s own records, export and retention stay open whatever the subscription is doing — because 29 CFR 1910.1200(g)(8), 1910.38(b) and 1910.1020(e) put those duties on the employer, and a vendor who gates them turns your compliance duty into their collections process. The full list, with the citation behind each item.

FAQ

Security questions a buyer actually asks

Three: the home page, the sign-in page and the sign-up page. Everything else on app.hazcomfast.com is disallowed in robots.txt, and the routes reached by a token — a container scan, a guest link, an invitation, the subcontractor portal, a document verification — answer with an X-Robots-Tag header of "noindex, nofollow" on top of that. Check it yourself: open https://app.hazcomfast.com/robots.txt, then run curl -I on any /scan or /guest URL. Belt and braces, because a token that leaks into a public index is a token you cannot take back.

No, and it is worth being plain about that rather than selling it as a duty. 29 CFR 1910.1200(g)(8) requires the sheet to be readily accessible during each work shift, with no barrier to immediate access; it says nothing about recording the consultation. 29 CFR 1910.1020(e) governs access to exposure and medical records and likewise does not require a log of who looked. What a read confirmation gives you is evidence for the training duty of 1910.1200(h)(1), which is a different question.

The lock acts on writing, never on reading. Every open jobsite stays readable, the sheets still open, the emergency screen still works, a worker still reaches their own records, and export stays available in full. That is not generosity: 29 CFR 1910.1200(g)(8) requires the sheet during each work shift, 1910.38(b) requires the emergency action plan to be kept in the workplace and available to employees, and 1910.1020(e) requires record access. A compliance product that manufactures its customer's violation has no defense. The full list, with the citation behind each item, is on the page about what a plan can never lock.

No. The refusal comes from the database rather than from the screen, so it holds against a direct API call as well as against a button, and it covers the record tables a hold can reach. A hold is also not deleted but released, with a reason, and a released hold cannot be rewritten afterwards. The retention clocks behind that are 29 CFR 1910.1020(d)(1)(ii), at least thirty years for an employee exposure record, and 29 CFR 1904.33(a), five years past the calendar year the OSHA 300 Log, the privacy case list, the annual summary and the 301 forms cover.

The export writes the apostrophe OWASP asks for in front of any cell that would start with =, +, - or @, with a tab or with a carriage return, so the cell arrives as text. OWASP itself notes that this defence is not reliable in Microsoft Excel once the CSV has been saved and reopened, so treat an export from any vendor the way you would treat any file from outside: open it in a text editor first if the contents are not yours.

Run curl -I https://app.hazcomfast.com/ and read the headers against the table above. Read https://app.hazcomfast.com/robots.txt. Run curl -I on a /scan URL and look for the noindex header. For the rest, the free tools on this site need no account at all, so you can see what the exports look like before anyone signs anything.

Found something this page gets wrong?

Every line here is a measurement, and a measurement can go stale. If one of them does not behave as written on the running application, that is a defect we want reported rather than a sentence we want defended. Tell us, and read how to test a legal hold on any product while you are at it.