Security

Built so one company can never see another’s property records.

This page says exactly how SiteWalk Pro protects what your team records on a walk — and, just as plainly, what we don’t claim. Everything here matches our Privacy Policy, which is the binding version.

Last reviewed September 21, 2026.

Isolated in the databaseEach company’s records are separated by row-level security, enforced in the database itself and tested at every schema change.
Encrypted everywhereAES-256 at rest, TLS in transit. Photos are private and served on links that expire.
Certified infrastructureSOC 2 Type II and ISO 27001 certified providers, hosted in the United States.
Backed up twiceDaily encrypted database backups, plus a nightly encrypted copy of every image to a second US provider.

Who can see what

Access follows how a property management company actually works. There is no public sign-up: SiteWalk Pro issues a company’s first administrator account, and every other account is an invitation from inside that company.

Company administrator

Sees every property in the company. The only role that can change someone’s role, remove them, or delete a property.

Property manager

Walks properties, logs issues, and produces documents for the properties assigned to them — all of them, or the specific ones the administrator chose. May add on-site staff to a property they manage, and no one else.

On-site staff

Walk and log issues on the properties they were invited to. They don’t add properties or produce documents.

Vendors

Never sign in. You download the packet or work order and send it from your own email; a vendor has no account and no view into your workspace.

Owners and principals

Receive the reports you send them. SiteWalk Pro never contacts an owner on its own.

Getting in

Inside the application

Isolation that code can’t bypass

Every company’s buildings, issues, photos and people are separated by row-level security policies that live inside the database. A bug in the application cannot reach past them, because the database refuses the query.

We test that rather than assume it. A standing test signs in as one company and attempts to read and to write another company’s records — it has to fail at both — and we run it against the database whenever we change how data is stored.

Photos are private

Walk photos, site plans and aerials sit in private storage. The app displays them through signed links that expire after one hour, so a copied link stops working and nothing is reachable by URL alone.

No card numbers, ever

Billing is handled entirely by Stripe. We keep your plan, your properties’ square footage and count, and Stripe’s customer reference. Card details never touch our systems.

Monitoring without your data

Error monitoring records technical logs — what failed and where — never issue text, names or photos. Access to production systems is limited to authorized SiteWalk Pro personnel and contractors bound by confidentiality obligations.

Where your data lives, and how it’s kept

Who else touches it

We don’t run our own servers. Your data is held and processed by a small set of established infrastructure providers under data-processing agreements. We’ll update this list before adding anyone new.

ServiceWhat it handlesWhere
SupabaseAccounts, database, and photo storage. SOC 2 Type II and ISO 27001 certified.United States
VercelHosting and delivery of the applicationUnited States
Backblaze B2Encrypted off-site backup copies of the images we store; never names, issues, or notesUnited States
MapboxTurning property addresses into map coordinates and fetching aerial imagery — addresses only, sent from our serverUnited States
StripePayment processingUnited States
SentryError monitoring — technical logs only, never walk data or photosUnited States
BrevoSending notification emails (name, issue title, link — never photos)European Union

Every piece of a customer’s property data stays in the United States. The one European provider sees an email envelope.

If something goes wrong

What we don’t claim

Security pages are where companies round up. We’d rather you know exactly where the line is.

As of September 2026

  • The certifications above belong to our infrastructure providers, not to SiteWalk Pro, LLC. We have not been independently audited under SOC 2 or ISO 27001 ourselves. We will pursue that when a customer’s requirements call for it.
  • The application has not yet had its own third-party penetration test. Our database provider is tested regularly; our code is not, beyond our own testing.
  • Multi-factor authentication for password sign-ins is not offered yet. Signing in with a Microsoft work account gives you your company’s MFA today.
  • No uptime guarantee. We aim to keep SiteWalk Pro running and warn before planned downtime, but we don’t currently offer a contractual SLA. Keep independent records of anything safety- or compliance-critical.

Questions from your IT team

Send them over. A security questionnaire, a specific control, a request for our providers’ certifications — we answer directly, in writing, from the people who built the product.

Read the Privacy Policy and Terms of Service.