Security
Security and trust
ConditionVault is built with security, isolation and auditability at its core. Here's what we can verify — no exaggerated claims.
Organisation isolation
Each organisation's data is isolated. Users can only access data belonging to their own organisation.
Role-based access
Granular roles — organisation owner, admin, inspector and viewer — each with appropriate permissions.
Audit events
Every property and report action is logged with actor type, timestamp and metadata for full traceability.
Report snapshots
Finalised reports are locked with SHA-256 integrity hashes. Snapshots are immutable and tamper-evident.
Tokenised public links
Shared reports and galleries use secure, time-limited tokens with expiry dates and revocation.
Private-note separation
Internal inspector notes are separated from tenant-visible content — never exposed in shared reports.
Data export
Your reports, photos and property data are exportable at any time. No lock-in.
Stripe-hosted payments
Payment management is handled by Stripe. We never store card numbers, CVC codes or bank details.
What we don't claim
We do not claim SOC 2, ISO 27001, Cyber Essentials, guaranteed GDPR compliance, specific uptime guarantees, or penetration testing unless and until verified evidence exists. We recommend independent legal and security review for your specific requirements.
Try ConditionVault
Start your 14-day free trial and see the security features in action.
No payment card required · Full core platform access · Your data remains exportable