For customers · Security
The controlsbehind yourdata.
What Inspect Point does to protect the information contractors put in it, stated as controls, not adjectives.
Controls on record
| Audit | SOC 2 Type II |
|---|---|
| Encryption | In transit and at rest |
| Sign-in | Azure AD single sign-on |
| Access | Roles, territories, portal |
| Payments | PCI-compliant processor |
| AI training | Not on your content |
| Leaving | Full export on cancel |
What is on record.
You own the data
You own all of your company and customer information, stored in the cloud with user-controlled access and SSL encryption. If you cancel, you get a full export of your data before the account closes.
SOC 2 Type II and GDPR-aligned practices
Inspect Point's controls are audited against SOC 2 Type II, and its data practices are aligned with GDPR. The audit report is available to customers and prospects under NDA through your account team.
Encrypted in transit and at rest
Data is encrypted in transit and at rest. The back office, the Customer Portal, and the field app all connect over SSL.
Single sign-on and user management
Azure Active Directory single sign-on lets your team sign in to the back office and the iPad app with their own directory credentials instead of separate passwords. Admins add and remove back-office users and technicians themselves.
Roles, territories, and portal permissions
Back-office users carry permissions by role, technicians see the work assigned to them, territories restrict which buildings a user or technician can reach, and Customer Portal contacts see only the reports, proposals, and invoices they have been granted.
Activity timelines on the records that matter
Buildings, deficiencies, and work orders carry an activity timeline of who did what and when. Inspect Point Assistant actions are previewed before they run, logged, reversible for 30 minutes, and can be restricted or switched off by an admin.
Your content is not used to train public models
The AI features work on your account's data to check your inspections and answer your questions. That content is not used to train public models, and every write the assistant makes waits for a person to confirm it.
PCI-compliant payment processing
Card and ACH payments run through a certified PCI-compliant payments partner. Card details are entered in the processor's checkout, not stored in Inspect Point.
Company-owned Apple devices on supported iOS
The field app runs on iPads, iPhones, and Apple-silicon Macs your company owns, on a supported iOS version. Older devices that cannot receive Apple's security updates lose access on a published schedule.
Request the
SOC 2 report.
Security questionnaires, the SOC 2 report, and anything above in more detail: ask your account team, or book a call.