Data Security at AnyInspect

Last updated: 8 April 2025

Understand our multi-layer approach to securing your data within our technical and business infrastructure.

Scope

This policy has been prepared to provide a clear understanding of the data storage and security model within the AnyInspect Platform, covering our generally available products including the mobile inspection app, web dashboard, and backend API services. Should any conflicts in documents exist, the AnyInspect Terms of Use should be relied upon.

The AnyInspect executive team, management, employees, and contractors alike have read, acknowledged, and agree to abide by this data security and availability policy. This policy defines our approach to securing your data.

Your obligations in securing platform data

Communicating over the internet has inherent risks. As you will read below, we have put many protocols in place; however, users should also implement strict security profiles within their organisation including but not limited to anti-virus software if you use the Windows operating system, up-to-date operating systems, and usage of secure evergreen browsers (Mozilla Firefox or Google Chrome).

Generally speaking, the greatest data security risk is social — for example, unauthorised access to the system provided by a current or former employee of an organisation. The AnyInspect platform provides strong data security protocols allowing you to minimise data theft and misuse.

Authentication and password management

AnyInspect uses Better Auth for authentication across all products, supporting email/password and Google OAuth sign-in methods. The platform enforces role-based access control (RBAC) with four distinct roles: owner, admin, inspector, and client. Each role has tailored permissions to ensure users only access the data and features relevant to their responsibilities.

New users are typically provided access by internal administrative users within their organisation. Users have the ability to change their password at any time. You and your employees are responsible for the security and confidentiality of personal login credentials.

You are responsible for revoking access for employees when they leave your organisation.

Password rotation is NOT encouraged, in line with NIST security guidelines. Strong password use IS encouraged, and a minimum password strength requirement along with common password prevention are enforced across all sign-up and password change forms.

Role-based access control

AnyInspect provides a structured role-based access control system with four permission levels:

  • Owner — Full administrative control over the organisation, billing, team management, and all inspection data.
  • Admin — Can manage inspections, reports, properties, inspectors, and organisational settings.
  • Inspector — Field-level access to assigned inspections, recording capabilities, and report submission.
  • Client — Read-only access to completed reports and invoices via the client portal.

We strongly recommend you invest time in understanding and structuring your user roles to minimise all data security risks.

AnyInspect internal security controls

AnyInspect has implemented the following internal security protocols.

Technological controls

  • Instituted controls on appropriate password strength required to log into all company equipment.
  • Implementing security logs of access to the customer platform.
  • Using firewall, TLS/HTTPS, and encryption technologies to protect all gateways and data pipelines.
  • Cloudflare for CDN, DDoS protection, DNS management, and WAF (Web Application Firewall).
  • Limiting employee access to only the relevant systems required within scope of each employee's role or responsibility.
  • Limiting and monitoring access to the support gateway through approved credentials using industry-standard encryption technologies.
  • Electronic logs and controls of all platform access.
  • Regulating all employee system controls and access.
  • Logging, monitoring, and tracking transmissions in a manner that is commercially reasonable (up to 12 months of historical log information).

Process controls

  • Policies and procedures dictating the access, usage, and disclosure of customer information.
  • Appointed manager for security control and auditing.
  • Restrictions of access to server keys and logs.
  • Review and investigations into any reported security issues provided by hosting providers and software providers.
  • Notification process of any security breaches to customers directly via email.

Standard operating environment for internal machines

All AnyInspect staff are equipped with devices that have automatic updates enabled, at-rest encryption, and short screen-lock timeouts. These devices also have their location tracked and can be locked or wiped remotely in the event of loss or theft.

Data hosting and infrastructure security

AnyInspect invests in technological, physical, and procedural processes to protect the security of our customers' data. Our infrastructure is built on industry-leading cloud services chosen for their security, reliability, and scalability.

Core infrastructure

  • Database — PostgreSQL with encryption at rest and in transit. The database is the central store for all inspection data, reports, user accounts, and organisational information.
  • File storage — Amazon Web Services (AWS) S3 for all uploaded files including inspection videos, photos, thumbnails, generated PDF reports, and organisation logos. S3 provides 99.999999999% (11 nines) durability and supports encryption at rest using AES-256.
  • Backend API — Express.js server handling all API requests, authentication, AI processing orchestration, and PDF generation.
  • Web dashboard — Next.js application for the admin dashboard, connecting directly to the database with server-side rendering for enhanced security.
  • Mobile app — React Native / Expo application with MMKV encrypted local storage for offline-first operation. Data is encrypted on-device and synced securely when connectivity is available.
  • Deployment — Coolify (self-hosted deployment platform) for automated deployments from GitHub, ensuring full control over the deployment pipeline.

Network and transport security

  • Cloudflare — All traffic is proxied through Cloudflare, providing DDoS protection, Web Application Firewall (WAF), SSL/TLS termination, and DNS management. Cloudflare Tunnel is used to securely connect our origin servers without exposing them directly to the internet.
  • All data in transit is encrypted using TLS/HTTPS. HTTPS is enforced for all traffic with no exceptions.
  • SSL certificates are automatically managed and rotated.

AWS S3 security

AWS S3, used for all file storage, supports security standards and compliance certifications including PCI-DSS, HIPAA/HITECH, FedRAMP, EU Data Protection Directive, and FISMA, helping satisfy compliance requirements for regulatory agencies globally. All data stored in S3 is encrypted at rest using AES-256 server-side encryption.

AnyInspect institutes tight controls internally on who has access to the AWS environment, limited to those members of the team directly involved in infrastructure operations.

AI processing and third-party data handling

AnyInspect uses artificial intelligence to automate inspection report generation. The following third-party services are used in our AI pipeline:

  • Deepgram — Used for transcribing audio from inspection video recordings. Audio data is transmitted securely via encrypted connections. Deepgram does not retain customer audio data after processing is complete and does not use customer data for model training.
  • Google Gemini — Used for AI analysis of transcriptions and extracted video frames against inspection schemas to auto-generate report items. Data is transmitted securely and is not used by Google for model training purposes.

In both cases, data sent to these services is limited to the minimum necessary for processing. No personally identifiable information (PII) beyond what is contained in the inspection recordings is transmitted. All transmissions use TLS encryption.

Payment processing

AnyInspect uses Stripe for all payment processing and subscription management. Stripe is a PCI DSS Level 1 certified payment processor — the highest level of certification available. AnyInspect does not store, process, or have access to full credit card numbers. All payment data is handled directly by Stripe's secure infrastructure.

Analytics

AnyInspect uses PostHog for product analytics across the mobile app, web dashboard, and marketing website. PostHog is used to understand product usage patterns and improve the user experience. Analytics data does not include sensitive inspection content or personally identifiable information beyond basic usage metrics.

Mobile application security

The AnyInspect mobile app is built with React Native and Expo, and includes the following security measures:

  • Encrypted local storage — MMKV (encrypted key-value storage) is used for all locally stored data including authentication tokens and cached inspection data.
  • Offline-first architecture — The app queues API calls locally when offline and syncs automatically when connectivity returns, using a secure sync engine with network monitoring.
  • Secure API communication — All communication between the mobile app and the backend API uses HTTPS with TLS encryption.
  • Authentication tokens — Session tokens are securely stored in encrypted storage and are validated on every API request.

Encryption summary

  • Data in transit — All data transmitted between clients (mobile app, web dashboard) and servers is encrypted using TLS/HTTPS. This includes API calls, file uploads, and all third-party service communications.
  • Data at rest — All data stored in the PostgreSQL database is encrypted at rest. All files stored in AWS S3 are encrypted at rest using AES-256 server-side encryption. Mobile app local storage uses MMKV encryption.
  • Backups — Database backups are encrypted and stored securely with restricted access.

Availability

AnyInspect provides all customers with a highly available service. Key components of the infrastructure are configured for redundancy and resilience. For scheduled maintenance, AnyInspect provides rolling updates with minimal downtime. The mobile app's offline-first architecture ensures inspectors can continue working even during periods of server unavailability, with data syncing automatically when connectivity is restored.

All data storage is encrypted at rest and stored in a highly durable environment. AWS S3 provides 99.999999999% durability (11 nines) for all uploaded files.

Location of hosted data

AnyInspect uses Amazon Web Services (AWS) for file storage and managed infrastructure services. The following definitions apply:

  • Primary Storage is defined as your data "at rest" and includes your customer database (data uploaded or entered) and all documents (files uploaded including videos, photos, and generated PDF reports).
  • Temporary Data is defined as derivatives generated from your Primary Storage necessary to deliver the product, including image thumbnails and video frame extractions used during AI processing.
  • Backups are defined as snapshots of your data at a point in time.

Primary Storage for file assets is hosted on AWS S3. The PostgreSQL database is hosted on managed infrastructure. Backups are stored securely with encryption at rest.

Access to your data and backups

AnyInspect allows customers to download their inspection reports as PDF documents directly through the platform. The web dashboard provides access to all inspection data, reports, photos, and recordings associated with your organisation.

AnyInspect maintains rolling backups of customer databases to minimise the risk of any cyber security or data centre incident impacting the integrity or availability of customer data.

Updates to policy

AnyInspect reserves the right to change this policy at any time. Any changes will become effective immediately upon publishing to the anyinspect.ai website. We will communicate material changes through appropriate channels to all active users.

If you have a request or complaint

To protect your data and the privacy of your users, we will need evidence of your identity before we can grant access to information or change settings for you.

We undertake to respond to complaints and requests within 5 working days and resolve them within 10 working days. If a request or complaint will take longer to resolve, we will provide you with a date by which we expect to respond.

Contact us

Should any items not be addressed in the above statement, please email [email protected] with any security concerns.

Helveton Limited, trading as AnyInspect.ai
1111B S Governors Ave #99667
Dover, DE 19904
United States