Your photos. Your data. Our job to protect it.
Every photo, project, and report you upload is protected by industry-standard encryption, strict access controls, and a clear commitment: we never sell your data, never train public AI models on it, and you can export or delete everything at any time.
How we protect your data.
Security isn't a feature you bolt on — it's how the product is built.
End-to-end encryption
TLS 1.2+ on every connection. AES-256 encryption at rest for every file on disk and in backup.
Role-based access control
Admin / Member / Viewer roles inside the app. Granular permissions on internal systems following least-privilege.
Session & credential security
Passwords hashed with a modern adaptive algorithm, scoped session tokens, and rate-limited authentication endpoints.
Application & access logging
Authentication and API activity is logged at the infrastructure layer for operational monitoring and incident review.
Monitoring & alerting
Automated monitoring for anomalous logins, brute-force attempts, and unusual data-export patterns.
Dependency & platform patching
Automated dependency vulnerability alerts, with security patches applied on a prioritised schedule.
Encrypted backups
Managed database backups with point-in-time recovery, and object storage with versioning enabled.
Data residency
Production data is stored in a US cloud region. Talk to us if your contract requires a specific region.
Vendor due diligence
Every subprocessor undergoes review against our security and privacy requirements before being granted access.
You own every byte.
Our position on customer data isn't aspirational marketing copy — it's how we've structured every part of the product.
You own your content.
You retain full rights to photos, videos, voice notes, documents, and project content.
We never sell your data.
No advertising, no data brokers, no third-party sharing of your project content.
No training on your data.
We do not use customer project content to train public AI models. Period.
Export anytime.
Per project or whole-account export. Photos export with original EXIF, plus JSON with tags, notes, and timestamps.
Delete anytime.
Account deletion purges personal data within 90 days. One-click — no retention dark patterns.
Portability built in.
Standard formats: JPEG/HEIC for photos, MP4 for video, JSON for metadata, PDF for reports. No proprietary lock-in.
Where your data actually lives.
No mystery. Here's the full stack.
| Layer | Provider | Regions | Purpose |
|---|---|---|---|
| Compute | Tier-1 enterprise cloud | United States | API servers, background workers, real-time sync |
| Object storage | Encrypted cloud object storage | United States | Photos, video, voice notes, document uploads |
| Database | Relational database | United States | Account, project, and metadata storage |
| CDN | Global edge CDN | Global edge network | Static asset delivery and DDoS protection |
| DNS | Enterprise DNS | Global | Domain resolution and routing |
Standards we align with — and what's coming.
We're transparent about what's certified, what's in progress, and what's planned.
Every third party who touches your data.
We notify customers via email at least 30 days before adding a new subprocessor.
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloud hosting & storage | Hosting, storage, compute | United States |
| CDN & DDoS protection | Content delivery, DNS, edge security | Global |
| Payment processing | Billing & payment processing | USA |
| AI processing | Photo auto-tagging, scope-of-work & damage detection | USA · never used to train public models |
| Transactional email | Account & notification email delivery | USA |
| Error monitoring | Application error monitoring (PII filtered) | USA |
| Customer support | In-app chat & support | USA |
Service availability
Target 99.9% monthly uptime. Every photo and file is held in replicated cloud object storage. Real-time status reporting.
Found a vulnerability?
We respond to security reports within 24 hours and treat researchers with respect.
Report a vulnerability
Email [email protected] with details. We'll acknowledge within 24 hours.
Questions about how we protect your data?
Security and privacy questions go to a human, not a queue. We answer within 24 hours.