Legal
Security
A summary of the controls we operate to protect property, tenancy and contractor data on the platform.
Last updated: 9 August 2026
Access control
Every record is protected by row-level access rules enforced in the database, not just in the interface. Tenants can reach only their own tenancy, contractors only the jobs assigned to them, landlords only their own portfolio, and staff only the properties and permissions granted to them. Internal staff notes are hidden from landlords, tenants and contractors.
Authentication
Accounts use email and password with hashed credential storage, session tokens issued by our managed authentication provider, and checks against known-breached passwords at sign-up and password change. Tenants and contractors join by invitation rather than open registration.
Data protection in transit and at rest
All traffic is served over HTTPS. Documents, inspection photographs and certificates are held in private storage and shared only through short-lived signed links. Card details are handled entirely by our payment provider.
Auditing and monitoring
Changes to properties, inspections, checklists, permissions and access grants are written to an append-only audit trail with the actor, timestamp and field-level differences. Automated backup verification runs on a schedule and restores are gated behind an approval workflow.
Reporting a vulnerability
If you believe you have found a security issue, email security@landlordinspectionservices.co.uk with enough detail to reproduce it. Please give us reasonable time to investigate before disclosing publicly, and do not access or modify data belonging to others while testing. We acknowledge reports within three working days.
Incidents
We maintain an internal incident and breach register. Where an incident is likely to result in a risk to individuals, we notify the Information Commissioner's Office within 72 hours and inform affected users without undue delay. See our privacy notice.
