Security

Last updated: 18 July 2026

An overview of how we protect your data. We describe only measures that are in place today; we do not claim certifications we do not hold.

Tenant isolation

Each customer organisation is a separate tenant. Company and project data are separated using database-level access controls, including PostgreSQL row-level security, together with role-based permissions.

Access control

Access within an organisation is role-based, and an account can be deactivated immediately to revoke access. Vendor-support access is limited, logged and attributable.

Encryption in transit and at rest

The website and application are served over HTTPS. Data is stored with our hosting and database provider, which encrypts data at rest. Evidence files such as photographs and drawings are held in private storage and served through short-lived signed links rather than public URLs.

Evidence integrity

Submitted diaries are protected from ordinary content editing. Reopening a submitted diary requires an explicit action and stated reason, and the reopen is recorded in the audit trail. These controls are intended to preserve a clear history of when the record was submitted and subsequently reopened.

Hosting

The primary application database, authentication data and evidence-file storage are hosted in London, United Kingdom. Other providers involved in application delivery, email, monitoring, billing and optional AI features may process limited data in additional locations. Details are provided in the service providers list in our Privacy Notice.

Reporting a vulnerability

If you believe you have identified a security vulnerability, please email hello@site-chronicle.com. Please provide enough information for us to understand and reproduce the issue, but do not access, download or disclose customer data. We will acknowledge and investigate responsible reports promptly.

Security | Site Chronicle