A HomeCheck report is only worth something if nobody can quietly change it. That makes security more than a compliance exercise for us - it is the product. This page explains, in concrete terms, how we protect your personal data and how we protect the integrity of the record itself. Found a problem? Tell us - we would rather hear it from you than from a tenant in a dispute.
01

Our Approach

We protect two different things, and they need different defences:

🔐 Your personal data

Account details, property addresses, video footage, payment records - kept confidential, encrypted, and only accessible to those who should see it.

🛡️ The integrity of the record

Evidence that cannot be edited after the fact, by either party or by us - because a record either party could alter would be worthless.

Three principles guide how we build: collect only what the service needs, restrict access to the fewest people possible, and make tampering detectable rather than merely discouraged.

02

Record Integrity

Every video is cryptographically signed at the point of recording. It cannot be edited, filtered, or uploaded from an external source - footage must be captured live through the HomeCheck app, not selected from a camera roll.

Each inspection carries the timestamp recorded at capture. Reports are generated from the original footage, which we retain unmodified; changing a report after the fact would break the signature, which is exactly the point.

Both sides see the same file. When a report is shared between a tenant and a landlord, it is the same record - there is no landlord version and no tenant version. Neither party can amend it, and neither can we.

Condition scores are produced by automated analysis of that footage. The limits of what automated analysis can and cannot tell you are set out in our Terms of Service.

03

Encryption

Where How it is protected
In transit All traffic between the app or website and our services runs over HTTPS using TLS 1.2 or above. We do not accept unencrypted connections.
At rest Video, reports, and database records are stored in Microsoft Azure and encrypted at rest with AES-256 by Azure Storage Service Encryption.
Passwords Stored only as salted one-way hashes. We cannot read your password, and nobody at HomeCheck can retrieve it - a reset is the only route back in.
Backups Backups inherit the same encryption and access restrictions as live data, and are held within the same regional boundary.
04

Where Your Data Lives

Our primary infrastructure runs on Microsoft Azure, in European data centres. Azure processes data for us under a Data Processing Agreement incorporating Standard Contractual Clauses.

Where data is processed outside the EEA or the UK - for example by an Azure service with global infrastructure - the transfer is covered by EU Standard Contractual Clauses and, for UK-specific transfers, the UK International Data Transfer Agreement. The detail is in our Privacy Notice, and you can request a copy of the safeguards at any time.

05

Access Control

Inside the product

Access to a property's records is governed by role. Tenants, landlords, and property managers attached to the same property see the reports for that property and nothing else. Adding someone to a property grants access; removing them ends it. No user can browse another property's records.

Inside HomeCheck

06

Payment Security

We do not store full card details on our servers - not encrypted, not anywhere. Card payments are handled by Stripe, a PCI DSS Level 1 service provider, and by Apple where you pay through the App Store or Apple Pay.

What we hold is the billing name, your plan, and the last four digits of the card, so you can recognise your own payment method. Nothing more.

07

Our Suppliers

We keep our supplier list deliberately short. Each one is bound by a data processing agreement and used for a specific purpose:

Supplier What they do
Microsoft Azure Hosting, blob storage for video, and the computer vision services that analyse inspection footage.
Stripe Card processing, subscriptions, and invoicing.
Apple App distribution, including pre-release builds via TestFlight, and payments made through the App Store or Apple Pay.

We do not sell personal data, and we do not use advertising networks or third-party trackers inside the app. The full list of who receives data, and why, is in our Privacy Notice.

08

App and Device Security

Keep the app updated. Security fixes only protect you once you are running the version that contains them.
09

Retention and Deletion

We keep data only as long as it serves a purpose. Inspection records are generally retained for the duration of the relevant tenancy plus six years, because that is how long a dispute about a deposit can realistically run. Payment records are kept for seven years to meet tax obligations.

When data is no longer needed, we delete it or irreversibly anonymise it - and anonymised data cannot be turned back into a person or a property. The full retention schedule is in our Privacy Notice, along with how to request early deletion.

10

Incident Response

We plan for the possibility that something goes wrong, because assuming otherwise is not a security strategy. If we detect a breach affecting personal data:

Step What happens
Contain We cut off the route in, revoke affected credentials, and preserve logs so the incident can be reconstructed accurately.
Assess We establish what data was involved, whose it was, and what the realistic risk to those people is.
Notify regulators Where the breach is notifiable, we report it to the ICO (UK) or the Data Protection Commission (Ireland) within 72 hours of becoming aware of it, as GDPR requires.
Notify you Where there is a high risk to your rights, we contact affected users without undue delay - telling you what happened, what data was involved, and what to do about it.
Fix and learn We close the root cause, not just the symptom, and record what changed so the same failure cannot recur quietly.

We will not downplay an incident or delay telling you to protect our own reputation. A company whose product is honest evidence cannot be dishonest about its own failures.

11

Reporting a Vulnerability

If you have found a security issue in the HomeCheck app, website, or API, please tell us at hello@homecheck.live with enough detail for us to reproduce it.

What we commit to

What we ask of you

We do not currently run a paid bug bounty. That does not make your report less welcome - it means we will thank you properly rather than pay you.
12

Your Part in This

Most real-world account compromises are not clever attacks on infrastructure. They are reused passwords and shared logins. A few things that genuinely help:

13

Certification Status

We would rather be straight with you than imply more than we have.

HomeCheck does not currently hold ISO 27001 or SOC 2 certification. We build on certified infrastructure - Microsoft Azure and Stripe hold those certifications for the services we use - and we apply the practices described on this page. If and when we complete formal certification ourselves, we will say so here, with the date and scope.

We comply with the UK GDPR and the EU GDPR as a data controller. What that means in practice, including your rights and how to exercise them, is set out in our Privacy Notice.

This page is reviewed as our practices change. The review date at the top of the page tells you when it was last checked.

14

Contact Us

Security Contact HomeCheck Ltd To report a vulnerability, ask about our security practices, or raise a concern about your account:

🔐 hello@homecheck.live
📧 privacy@homecheck.live — data protection and breach enquiries
🌐 homecheck.live

We acknowledge security reports within 5 working days.