Skip to content

MeetInspect keeps fieldwork moving even when the signal stops

MeetInspect

Security

Protecting inspection records requires clear controls and careful habits

MeetInspect uses access controls, encrypted network transport and organisation-scoped authorisation to operate the service. No internet service can guarantee absolute security.

Authorised reviewer checking a MeetInspect inspection record

What it covers

Security across the inspection lifecycle

Technical controls work best when workspace administrators also manage access, devices and retention responsibly.

01

Account and workspace access

Members authenticate to access a workspace, and roles separate administration, inspection and viewing responsibilities.

  • Admin, Inspector and Viewer roles
  • Organisation-scoped access
  • Prompt member removal
02

Data in operation

MeetInspect uses encrypted network transport and service providers needed for authentication, storage, media, billing, email and product operation.

  • Encrypted transport
  • Controlled service providers
  • Operational monitoring
03

Mobile field safeguards

Unsynchronised inspection data may remain on the device, so users should protect device access and never sign out or uninstall while uploads are pending.

  • Device protection
  • Visible sync checks
  • Safe incident reporting

In practice

Shared security responsibilities

1

Administrators

Invite current work addresses, grant the least access needed and remove members promptly when access is no longer required.

2

Inspectors

Protect device credentials, verify synchronisation and report a lost device or suspicious access immediately.

3

MeetInspect

Operate and monitor the service, restrict provider access to operational needs and respond to reported security or privacy concerns.

In depth

Security questions worth asking of any inspection system

Inspection data is more sensitive than it appears

Inspection records are easy to underestimate. They routinely contain residential addresses, occupancy information, photographs of people's homes and interiors, contact details for residents and owners, and timestamps establishing when a property was empty. Collectively that is a meaningful privacy surface, even when no single field looks sensitive.

Treating it accordingly — restricting access by role, limiting what leaves the system, and being deliberate about retention — is proportionate rather than cautious.

  • Restrict access to inspection content by role rather than by convention
  • Be deliberate about who can export or share completed records
  • Consider what photographs capture incidentally, not only their subject
  • Establish retention periods rather than keeping everything indefinitely

Access control follows the organisation, not the individual

Inspection work involves employees, contractors and occasional users, and access frequently outlives the engagement that justified it. The practical control is to scope access to an organisation and a role, then review membership on a schedule rather than relying on offboarding to be remembered.

This is more effective than tightening permissions on individual records, because the failure mode in practice is not over-broad record permissions — it is accounts that should no longer exist.

Devices in the field

Field inspection puts organisational data on mobile devices that travel, get left in vehicles and are occasionally lost. Device-level protection — passcodes, encryption, remote wipe where the estate supports it — is part of the security posture of any inspection programme, and it sits outside the inspection software itself.

The corresponding process control is knowing what was on a device: which inspections were captured and whether they had synchronised at the time it went missing.

Common questions

Why is inspection data considered sensitive?
Because it aggregates residential addresses, occupancy patterns, interior photographs, resident contact details and timestamps showing when properties were unoccupied. Individually unremarkable fields become a meaningful privacy surface in combination.
What is the most common access-control failure?
Accounts outliving the engagement that justified them, particularly for contractors and occasional users. Scheduled membership review addresses this more effectively than tightening permissions on individual records.
What should happen if a field device is lost?
Beyond the organisation's device policy, establish what inspection work was on it and whether that work had synchronised. Captured-but-unsynchronised inspections exist in only one place, which makes them both a data-loss and a data-exposure question.

Next step

Explore the related guidance, or speak with MeetInspect about the inspection your team needs to run.