Security
Your inspection data is your business. We take that seriously.
Security approach
FireInspected uses HTTPS for web and API traffic, secure HttpOnly session cookies, organization-scoped access checks, tenant-aware queries, rate limiting, security headers, and private object-storage boundaries. Public waitlist and template forms use same-origin edge handlers, managed bot detection, input limits, honeypots, consent validation, and best-effort per-edge rate limits; these are not a substitute for a durable edge policy or provider monitoring. The paid beta is still being hardened; these controls are not a certification or guarantee.
Hosting and data handling
The public site and application run as separate deployments on managed cloud infrastructure. Photos and generated reports are stored in private object storage when configured. Actual data location, retention, and provider settings can vary by environment; we provide current control details during onboarding when they are material to your use of the service.
Data ownership
Your organization retains its customer and inspection data. We do not sell inspection data. Export and deletion are available through the application or support process where implemented, but the current beta export does not yet include every stored object such as photos or generated PDFs, and deletion may require an asynchronous operator-assisted process. See the Privacy Policy for the current boundaries.
Authentication and access
Sign-in uses a supported third-party identity provider in the beta; a separate business email can be collected for company contact and report delivery. Secure server-side sessions and organization roles control access. Email/password sign-in and two-factor authentication are not currently offered.
Beta status and attestations
FireInspected is an early paid beta. We are not claiming SOC 2, ISO 27001, PCI DSS, or any other independent security attestation for the application. Payment details are handled by a specialized payment processor rather than stored by FireInspected. Customers should evaluate whether the beta is appropriate for their data and request current control details before onboarding.
Backups and recovery
Backup and restore operations are part of the deployment readiness work and are not represented as a completed daily or point-in-time guarantee on this page. Customers should keep their own operational copies of important records while the beta recovery process is being validated.
Report a security issue
If you discover a security vulnerability, please email security@fireinspected.com with enough detail to reproduce it. We will acknowledge reports as soon as reasonably practical; we do not promise a fixed response time while the product is in beta.