SnagActionHomeReport a concern

Security overview · product preview

Evidence stays account-bound.

The current architecture keeps project records, photographs and issued revisions behind the signed-in user identity.

Honest scope. This page describes implemented controls. It does not claim a certification, independent penetration test, SLA, formal incident-response programme or regulatory compliance audit.

Authentication and ownership

Protected requests use the platform-provided signed-in identity. Project, report and photograph queries check that identity on the server; client-side buttons are not treated as authorization.

Storage

Structured records and ownership metadata are stored in the site database. Photograph bytes are stored separately in private object storage. Photograph delivery checks the requesting owner before reading the object.

Uploads and deletion

Uploads are limited to supported image types and sizes. Larger files are transferred in bounded chunks. Project and account deletion remove associated records and stored photograph objects; confirmation is required for destructive actions.

AI data minimisation

The AI drafting endpoint is server-side and requires authentication. It sends the smallest relevant text fields, disables response storage in the API request and never asks the model to decide severity, responsibility or repair acceptance.

Known preview limitations

  • No independent security audit has been completed.
  • Temporary offline copies can remain on a device controlled by the user.
  • Voice notes currently remain temporary in the active browser session.
  • Payment processing and contractor portals are not active.

Report a security or data concern through the private request form.

Last updated 30 August 2026TermsPrivacyContact