The answers your IT team will ask for.
A short, honest summary for a security review: how access works, where data sits, what leaves the platform and what you can take with you. Send this to whoever is asking.
Section 01How to do it
-
01
Establish who can see what
Customer workspaces are separated. Inside a workspace, access is by role — owner, manager or inspector. Clients see only their own properties, through a portal with its own login.
-
02
Turn on two-factor across the workspace
Two-factor authentication is available on every plan for your team and for portal users, with a workspace-wide policy, trusted devices for repeat logins, and remote sign-out of every other session.
-
03
Settle the hosting question
We are a UK company and the infrastructure runs in EU regions. If your policy needs a named region, a data residency commitment or anything in writing, ask before you roll out and we will confirm what applies to you.
-
04
Check the audit trail yourself
Activity keeps a full trail of team changes, logins and record edits, alongside every email the system has sent. It exports as CSV.
-
05
Deploy nothing
A browser. No agent, no MDM package, no desktop installer. Normal HTTPS access is the whole requirement, and updates need no rollout.
-
06
Agree the exit before you need it
PDF and CSV exports on demand, no request process and no export fee. Account deletion is available from within the app.
Section 02What the app actually does here
- Two-factor authentication is available on every plan, by authenticator app or email code
- Eight single-use recovery codes are issued, and can be regenerated
- Trusted devices can be remembered, and all of them forgotten in one action
- An owner can sign out every other device at once
- An owner can require two-factor authentication across the whole workspace
- The Activity page records team changes, logins and record edits, and exports as CSV
- Client portal users have their own separate two-factor authentication
- Workspace deletion runs on a 30-day grace window before anything is destroyed
Section 03What goes wrong
Every one of these has cost somebody real time. They are cheap to avoid and expensive to unwind.
It does, and that is the point — capture happens where signal does not.
Set the workspace policy. It is one setting and it is much easier before habits form.
They defeat the audit trail. Trusted devices give you the convenience without losing attribution.
Section 04Questions
Q01
Do you support SSO?
Q02
Where is our data hosted?
Q03
What happens when someone leaves?
Q04
Can we delete everything?
Section 05Related
Guides help. Doing it helps more.
Everything above is checkable inside the trial, on a real building, with nothing held back and no card required.
7-day trial · No card · Cancel anytime