Security

Last updated: 26 August 2026

An overview of how we protect your data. We describe only measures that are in place today; we do not claim certifications we do not hold.

Tenant isolation

Each customer organisation is a separate tenant. Company and project data are separated using database-level access controls, including PostgreSQL row-level security, together with role-based permissions.

Access control

Access within an organisation is role-based, and an account can be deactivated immediately to revoke access. New and reset passwords are checked against known data-breach corpora and rejected if they have appeared in a public breach. Vendor-support access is limited, logged and attributable: our support staff work through a dedicated support account for your organisation rather than signing in as one of your people.

Signing in and two-factor authentication

People sign in with an email address and password, with a single-use link sent to their email address, or with “Sign in with Microsoft” using their organisation's existing Microsoft 365 work account. Microsoft sign-in is available only to people who have already been invited to an organisation: it connects an existing account to a verified work identity, and cannot be used to create a new one.

The accounts that can invite people, change roles and export company data must also complete two-factor authentication using an authenticator app. The code is requested whichever sign-in method was used, including Microsoft sign-in, and the requirement is enforced by our servers rather than in the browser alone. Site users are deliberately not asked for a code, so that recording work on site stays quick. If an administrator loses their device, their enrolled app can be cleared through our audited support process, and that change is recorded in your audit trail.

Encryption in transit and at rest

The website and application are served over HTTPS. Data is stored with our hosting and database provider, which encrypts data at rest. Evidence files such as photographs and drawings are held in private storage and served through short-lived signed links rather than public URLs.

Evidence integrity

Submitted diaries are protected from ordinary content editing. Reopening a submitted diary requires an explicit action and stated reason, and the reopen is recorded in the audit trail. Before any reopened diary can change, its full content is preserved automatically as a version, and those preserved versions are visible in the application and included in your data export.

The audit trail itself is tamper-evident: each entry is cryptographically linked to the one before it in your organisation's own chain, so a later alteration, insertion or deletion within the trail is detectable by recomputation. Your administrators can export the full trail, including the chain, at any time.

Hosting

The primary application database, authentication data and evidence-file storage are hosted in London, United Kingdom. Other providers involved in application delivery, email, monitoring, billing and optional AI features may process limited data in additional locations. Details are provided in the service providers list in our Privacy Notice.

Reporting a vulnerability

If you believe you have identified a security vulnerability, please email hello@site-chronicle.com. Please provide enough information for us to understand and reproduce the issue, but do not access, download or disclose customer data. We will acknowledge and investigate responsible reports promptly.

Security | Site Chronicle