Skip to content
Two modules, one subscription EU hosted Built inside a working fire door company
For IT & procurement

The answers your IT team will ask for.

A short, honest summary for a security review: how access works, where data sits, what leaves the platform and what you can take with you. Send this to whoever is asking.

4 min read ITProcurementOwners

Section 01How to do it

  1. 01

    Establish who can see what

    Customer workspaces are separated. Inside a workspace, access is by role — owner, manager or inspector. Clients see only their own properties, through a portal with its own login.

  2. 02

    Turn on two-factor across the workspace

    Two-factor authentication is available on every plan for your team and for portal users, with a workspace-wide policy, trusted devices for repeat logins, and remote sign-out of every other session.

  3. 03

    Settle the hosting question

    We are a UK company and the infrastructure runs in EU regions. If your policy needs a named region, a data residency commitment or anything in writing, ask before you roll out and we will confirm what applies to you.

  4. 04

    Check the audit trail yourself

    Activity keeps a full trail of team changes, logins and record edits, alongside every email the system has sent. It exports as CSV.

  5. 05

    Deploy nothing

    A browser. No agent, no MDM package, no desktop installer. Normal HTTPS access is the whole requirement, and updates need no rollout.

  6. 06

    Agree the exit before you need it

    PDF and CSV exports on demand, no request process and no export fee. Account deletion is available from within the app.

Section 02What the app actually does here

  • Two-factor authentication is available on every plan, by authenticator app or email code
  • Eight single-use recovery codes are issued, and can be regenerated
  • Trusted devices can be remembered, and all of them forgotten in one action
  • An owner can sign out every other device at once
  • An owner can require two-factor authentication across the whole workspace
  • The Activity page records team changes, logins and record edits, and exports as CSV
  • Client portal users have their own separate two-factor authentication
  • Workspace deletion runs on a 30-day grace window before anything is destroyed

Section 03What goes wrong

Every one of these has cost somebody real time. They are cheap to avoid and expensive to unwind.

Assuming a browser app cannot work offline

It does, and that is the point — capture happens where signal does not.

Leaving 2FA optional and hoping

Set the workspace policy. It is one setting and it is much easier before habits form.

Shared logins on site devices

They defeat the audit trail. Trusted devices give you the convenience without losing attribution.

Section 04Questions

Q01

Do you support SSO?

Not today. There is no SAML or OIDC single sign-on, and it is not part of the standard setup — accounts are held in the platform with two-factor authentication and a workspace-wide policy the owner can enforce. If SSO is a hard requirement for your IT policy, tell us before you roll out rather than discovering it at the end of a review.
Q02

Where is our data hosted?

EU regions, and we are a UK company. If your procurement process needs that in writing, ask us.
Q03

What happens when someone leaves?

Revoke their access and the records stay. That is the argument for inviting inspectors into your workspace rather than receiving their PDFs.
Q04

Can we delete everything?

Yes. Account deletion is available in the app; export your PDFs and CSVs first if you want to keep the records. See the privacy policy →

Section 05Related

Start today

Guides help. Doing it helps more.

Everything above is checkable inside the trial, on a real building, with nothing held back and no card required.

7-day trial · No card · Cancel anytime