Skip to main content

Security

Security and trust

ConditionVault is built with security, isolation and auditability at its core. Here's what we can verify — no exaggerated claims.

Organisation isolation

Each organisation's data is isolated. Users can only access data belonging to their own organisation.

Role-based access

Granular roles — organisation owner, admin, inspector and viewer — each with appropriate permissions.

Audit events

Every property and report action is logged with actor type, timestamp and metadata for full traceability.

Report snapshots

Finalised reports are locked with SHA-256 integrity hashes. Snapshots are immutable and tamper-evident.

Tokenised public links

Shared reports and galleries use secure, time-limited tokens with expiry dates and revocation.

Private-note separation

Internal inspector notes are separated from tenant-visible content — never exposed in shared reports.

Data export

Your reports, photos and property data are exportable at any time. No lock-in.

Stripe-hosted payments

Payment management is handled by Stripe. We never store card numbers, CVC codes or bank details.

What we don't claim

We do not claim SOC 2, ISO 27001, Cyber Essentials, guaranteed GDPR compliance, specific uptime guarantees, or penetration testing unless and until verified evidence exists. We recommend independent legal and security review for your specific requirements.

Try ConditionVault

Start your 14-day free trial and see the security features in action.

No payment card required · Full core platform access · Your data remains exportable