This policy sets out the technical and organisational measures spanSense uses to protect Customer Data and personal data processed through the spanSense platform and the spanSense Field companion app.
spanSense Ltd · Registered in England and Wales, company no. 17464577 · Registered office: 8 Howard Street, Reading, RG1 7XS
1.1This policy describes how we protect the confidentiality, integrity, and availability of data processed through the Service, including Customer Data and personal data. It supplements, and should be read alongside, our Privacy Policy.
1.2This policy applies to spanSense's own application and infrastructure. It does not cover security measures within a Customer's own organisation, such as how the Customer manages its Authorised Users' devices or credentials.
2.1The Service is hosted using established, reputable cloud providers rather than self-managed servers, so that physical and network-level security is handled by providers who specialise in it:
| Provider | Role |
|---|---|
| Render | Application hosting |
| Supabase | Our PostgreSQL database, and storage of uploaded photographs and files |
2.2All traffic between your device and our servers is encrypted in transit using HTTPS.
3.1Passwords are never stored in plain text. They are hashed using bcrypt, an industry-standard salted hashing algorithm designed to resist brute-force attacks, before being stored.
3.2We support optional two-factor authentication (2FA) using time-based one-time passcodes (TOTP), compatible with standard authenticator apps (e.g. Google Authenticator, Microsoft Authenticator). We recommend Customers enable this for all accounts, particularly administrative ones.
3.3Sessions are managed server-side: authentication state is stored in our database rather than in a token held entirely by the browser, allowing sessions to be invalidated centrally if needed.
4.1The Service uses role-based permissions, so that what an Authorised User can view or change within an account reflects their assigned role.
4.2Internal access to production systems and data is limited to personnel who need it to operate and support the Service.
5.1Structured Customer Data (structures, inspections, defects, and related records) is stored in a PostgreSQL database that is not directly reachable from the public internet outside of the Service's own application layer.
5.2Uploaded photographs and files are stored in a private storage bucket. They are never given a public URL; instead, access is granted only through short-lived, individually-generated signed links, generated on demand by the Service for an authenticated user.
6.1The spanSense Field app can queue inspection data and photographs locally on a device when working with no signal, syncing to our servers once connectivity resumes. Data queued in this way is only as secure as the device it is held on, so we recommend Customers apply their own device-level protections (e.g. a passcode or biometric lock) on devices used for fieldwork.
7.1We monitor for and apply security updates to the software libraries and infrastructure the Service depends on.
7.2Changes to the Service go through review before being deployed to the live environment.
8.1If we become aware of a security incident affecting your data, we will investigate promptly and notify affected Customers without undue delay, and in any event within the timeframes required by applicable data protection law where the incident constitutes a personal data breach.
9.1If you believe you have found a security vulnerability in the Service, please report it to [email protected] rather than disclosing it publicly, so we can investigate and address it.
10.1We may update this policy as our security practices evolve. Material changes will be reflected in the "Last updated" date above.