Skip to main content

Security

Security practices for property data

These are the controls our systems and processes are designed to support. We describe them plainly, including where they fall short of an independently verified certification, rather than claiming compliance we have not undergone.

We do not claim SOC 2, ISO 27001, HIPAA, FedRAMP, or any other formal certification. Where a control below has not been independently audited, we say so.

Least privilege access

Staff and system accounts are designed to support access scoped to what a role actually requires — capture crews, reviewers, and support staff do not share a single broad account, and engagement records are scoped to the team working that engagement.

Encryption in transit

Connections to our workspace, client portal, and file transfer paths are designed to run over TLS. We do not transmit capture data or credentials over unencrypted connections.

Encryption at rest

Object storage housing capture files and the databases behind the property record are designed to use provider-managed encryption at rest, consistent with standard cloud storage practice.

Secure, expiring object links

Large capture files are shared through time-limited, access-controlled links rather than open public URLs, so a shared link cannot be reused indefinitely once an engagement or access grant ends.

Access logging

Access to property records and deliverable downloads is designed to be logged, so an unusual access pattern or a disputed download can be investigated after the fact.

Tenant and project separation

Each client's property records are logically separated by engagement and account, so one client's capture data, imagery, and deliverables are not visible from another client's workspace.

Backups

Capture data and the property record database are designed to be backed up on a regular schedule, with restoration tested periodically rather than assumed.

Retention controls

Retention periods are set by the engagement contract. Systems are designed to support enforcing those periods and flagging records approaching a scheduled deletion or review date.

Incident response

What happens if something goes wrong

  • Suspected incidents are triaged immediately: scope, affected records, and access paths are identified first.
  • Affected clients are notified with what is known, what is being done, and what remains under investigation, as required by the engagement contract and applicable law.
  • Access credentials or links implicated in an incident are revoked or rotated as part of containment.
  • A written summary of cause and remediation is produced once the investigation is closed.

Vendor boundaries

SuiteDash and other vendor boundaries

Commercial relationship data — proposals, contracts, invoices, messages, and support tickets — is held in SuiteDash, a third-party CRM platform, under its own security practices and our contractual terms with it. Property capture data is not stored in SuiteDash and is not duplicated across systems.

No raw technical files in GitHub

Source code repositories are used for application code, not as a store for client capture files, imagery, or point clouds. Technical property data lives in dedicated object storage and the property record workspace, not in version control.

No secrets in the browser

Credentials, API keys, and service secrets are kept server-side. The public website and client-facing interfaces are designed not to ship secret values to the browser.

Responsible disclosure

Report a security concern

If you believe you have found a security issue affecting our systems or a client's property data, tell us before disclosing it publicly.

Contact for security reports

Email support@lodgingconnections.com with a description of the issue and steps to reproduce it if known. We will acknowledge receipt, investigate, and follow up with what we found and what we did about it. Please give us a reasonable window to address a report before any public disclosure.

For how captured property data itself is divided, minimized, and retained, see data handling. For the broader picture of how we establish trust, see trust.

Next step

Have a security requirement for an engagement?

Tell us your requirements up front and we will tell you plainly what we can and cannot commit to.