Our Approach
We protect two different things, and they need different defences:
Account details, property addresses, video footage, payment records - kept confidential, encrypted, and only accessible to those who should see it.
Evidence that cannot be edited after the fact, by either party or by us - because a record either party could alter would be worthless.
Three principles guide how we build: collect only what the service needs, restrict access to the fewest people possible, and make tampering detectable rather than merely discouraged.
Record Integrity
Every video is cryptographically signed at the point of recording. It cannot be edited, filtered, or uploaded from an external source - footage must be captured live through the HomeCheck app, not selected from a camera roll.
Each inspection carries the timestamp recorded at capture. Reports are generated from the original footage, which we retain unmodified; changing a report after the fact would break the signature, which is exactly the point.
Condition scores are produced by automated analysis of that footage. The limits of what automated analysis can and cannot tell you are set out in our Terms of Service.
Encryption
| Where | How it is protected |
|---|---|
| In transit | All traffic between the app or website and our services runs over HTTPS using TLS 1.2 or above. We do not accept unencrypted connections. |
| At rest | Video, reports, and database records are stored in Microsoft Azure and encrypted at rest with AES-256 by Azure Storage Service Encryption. |
| Passwords | Stored only as salted one-way hashes. We cannot read your password, and nobody at HomeCheck can retrieve it - a reset is the only route back in. |
| Backups | Backups inherit the same encryption and access restrictions as live data, and are held within the same regional boundary. |
Where Your Data Lives
Our primary infrastructure runs on Microsoft Azure, in European data centres. Azure processes data for us under a Data Processing Agreement incorporating Standard Contractual Clauses.
Where data is processed outside the EEA or the UK - for example by an Azure service with global infrastructure - the transfer is covered by EU Standard Contractual Clauses and, for UK-specific transfers, the UK International Data Transfer Agreement. The detail is in our Privacy Notice, and you can request a copy of the safeguards at any time.
Access Control
Inside the product
Access to a property's records is governed by role. Tenants, landlords, and property managers attached to the same property see the reports for that property and nothing else. Adding someone to a property grants access; removing them ends it. No user can browse another property's records.
Inside HomeCheck
- Access to production systems is limited to the small number of people whose job requires it, on a least-privilege basis;
- Administrative accounts require strong authentication, and access is logged;
- No one at HomeCheck watches your footage as a matter of course. Analysis is automated. A person only views footage if you raise a support issue that cannot be resolved otherwise;
- Access is reviewed when roles change and revoked when someone leaves.
Payment Security
We do not store full card details on our servers - not encrypted, not anywhere. Card payments are handled by Stripe, a PCI DSS Level 1 service provider, and by Apple where you pay through the App Store or Apple Pay.
What we hold is the billing name, your plan, and the last four digits of the card, so you can recognise your own payment method. Nothing more.
Our Suppliers
We keep our supplier list deliberately short. Each one is bound by a data processing agreement and used for a specific purpose:
| Supplier | What they do |
|---|---|
| Microsoft Azure | Hosting, blob storage for video, and the computer vision services that analyse inspection footage. |
| Stripe | Card processing, subscriptions, and invoicing. |
| Apple | App distribution, including pre-release builds via TestFlight, and payments made through the App Store or Apple Pay. |
We do not sell personal data, and we do not use advertising networks or third-party trackers inside the app. The full list of who receives data, and why, is in our Privacy Notice.
App and Device Security
- The app collects device identifiers only for session management and crash reporting - never for advertising or cross-site tracking;
- Footage is uploaded over an encrypted connection and is not left sitting in your device's public photo library;
- We patch dependencies and ship security fixes as part of our normal release cycle;
- Some builds are distributed as pre-release software through Apple TestFlight. Pre-release builds may contain defects - see section 9 of our Terms.
Retention and Deletion
We keep data only as long as it serves a purpose. Inspection records are generally retained for the duration of the relevant tenancy plus six years, because that is how long a dispute about a deposit can realistically run. Payment records are kept for seven years to meet tax obligations.
When data is no longer needed, we delete it or irreversibly anonymise it - and anonymised data cannot be turned back into a person or a property. The full retention schedule is in our Privacy Notice, along with how to request early deletion.
Incident Response
We plan for the possibility that something goes wrong, because assuming otherwise is not a security strategy. If we detect a breach affecting personal data:
| Step | What happens |
|---|---|
| Contain | We cut off the route in, revoke affected credentials, and preserve logs so the incident can be reconstructed accurately. |
| Assess | We establish what data was involved, whose it was, and what the realistic risk to those people is. |
| Notify regulators | Where the breach is notifiable, we report it to the ICO (UK) or the Data Protection Commission (Ireland) within 72 hours of becoming aware of it, as GDPR requires. |
| Notify you | Where there is a high risk to your rights, we contact affected users without undue delay - telling you what happened, what data was involved, and what to do about it. |
| Fix and learn | We close the root cause, not just the symptom, and record what changed so the same failure cannot recur quietly. |
We will not downplay an incident or delay telling you to protect our own reputation. A company whose product is honest evidence cannot be dishonest about its own failures.
Reporting a Vulnerability
If you have found a security issue in the HomeCheck app, website, or API, please tell us at hello@homecheck.live with enough detail for us to reproduce it.
What we commit to
- We acknowledge reports within 5 working days;
- We will tell you our assessment and keep you posted while we fix it;
- We will not pursue legal action against anyone who reports a genuine issue in good faith under the terms below, and we are happy to credit you when the fix ships.
What we ask of you
- Use only your own account and test data - do not access, modify, or store anyone else's property records, footage, or personal data;
- No denial-of-service testing, spam, social engineering of our staff or users, or physical attacks;
- Give us a reasonable opportunity to fix the issue before disclosing it publicly.
Your Part in This
Most real-world account compromises are not clever attacks on infrastructure. They are reused passwords and shared logins. A few things that genuinely help:
- Use a strong, unique password for HomeCheck, and a password manager to hold it;
- Do not share your login. If a colleague needs access, give them their own account;
- Keep the app updated, and keep your phone's operating system current;
- Tell occupants when you are making a video record of a property - it is their home, and in many cases the law requires it;
- Export and keep your own copy of any report you may need to rely on later;
- If something looks wrong on your account, tell us immediately rather than waiting to be sure.
Certification Status
We would rather be straight with you than imply more than we have.
We comply with the UK GDPR and the EU GDPR as a data controller. What that means in practice, including your rights and how to exercise them, is set out in our Privacy Notice.
This page is reviewed as our practices change. The review date at the top of the page tells you when it was last checked.
Contact Us
🔐 hello@homecheck.live
📧 privacy@homecheck.live — data protection and breach enquiries
🌐 homecheck.live
We acknowledge security reports within 5 working days.