Skip to content
Hovermarks

Security & trust

Built for compliance, including our own.

Multi-tenant isolation, Microsoft Entra SSO with MFA enforced on every account, encryption at rest and in transit, Azure UK South hosting with geo-replicated backups in UK West, and GDPR-aligned processing. US residency on the roadmap.

Azure UK South (primary)Geo-replicated to UK WestAzure Postgres + BlobGDPR-alignedEmail sign-in (Email-OTP MFA)BYO Entra SSO (Professional+)PITR backup · drilled quarterly

We treat security like a product feature, not a checkbox. Hovermarks is built on the same Azure primitives you'd use to run a regulated workload of your own.

The pillars of our trust posture

Each one is documented in our trust packet (available under NDA). The full controls catalogue is published in our Information Security Policy.

Read the policy: /legal/information-security-policy. Covers governance, risk management, access control, cryptography, operations, supplier security, incident management, business continuity, and compliance.

  • Multi-tenant isolation

    Every customer gets a logically isolated tenant. Tenant isolation is enforced through query filters that apply automatically to every database read, scoped to the authenticated tenant claim. Foundational tests fail loudly the moment a query forgets the tenant filter.

  • Microsoft Entra ID SSO

    Microsoft Entra ID with PKCE. MFA is enforced on every sign-in by Conditional Access on the Hovermarks identity tenant. No opt-in, no plan gate. Professional and Enterprise customers can also federate to their own Entra tenant and layer their own Conditional Access on top; talk to sales to enable. No shared service accounts, no orphaned access.

  • Email sign-in with MFA on every account, every plan

    Every user signs in with their email address and a password, with a one-time code sent to their verified email, enforced on every account, every plan. Identity is handled by Microsoft Entra External ID. MFA is enforced by Conditional Access on the Hovermarks identity tenant, required on every account, on every plan, including Starter trials. No SMS in the loop. Enterprise customers can also layer their own Entra Conditional Access on top to add device compliance, trusted-network rules, or stricter session policies. Session integrity is verified on every API call via signed JWTs with short expiry.

  • Encryption at rest and in transit

    TLS 1.2+ in transit on every request. Encryption at rest via Microsoft-managed keys (Azure Postgres Flexible Server data encryption + Storage SSE), with strict per-tenant data isolation enforced at the application layer.

  • Data residency: UK South + UK West

    Customer data is hosted primarily in Microsoft Azure UK South, a Tier IV-equivalent Microsoft datacentre with the same security controls as Azure US regions. Database records and blob attachments (photos, report files, tenant logos) are geo-replicated to Azure UK West for regional disaster recovery. Both are UK-sovereign Microsoft datacentres, so your data stays in the UK end-to-end. UK GDPR is functionally equivalent to GDPR; our DPA includes EU Standard Contractual Clauses for cross-border transfer. US data residency in Azure East US is on the roadmap for Enterprise customers; talk to us if it's a procurement requirement.

  • GDPR-aligned by design

    Soft-delete with 30-day restore window. Per-tenant data export to JSON. Hard-delete after retention with blob cleanup and a tamper-evident ledger entry. Customer data hosted in Azure UK South under UK GDPR (functionally equivalent to GDPR), with geo-replicated backups in UK West and EU SCCs available in our DPA.

  • Tamper-evident audit log

    Every meaningful action (sign-in, asset edit, inspection submit, report export) is recorded with actor, timestamp, and IP, on an append-only log. Writes happen for every tenant; in-dashboard search and filter is gated to Professional+.

  • Auditor pack verification

    TenantAdmin can generate a single tamper-evident PDF that bundles completed inspections, the matching audit-log slice, and a cryptographic verification block. The auditor or insurer follows the printed verification URL to independently re-check the chain. No Hovermarks login required for them. (Professional and Enterprise.)

  • Multi-tenant identity (one user, many organisations)

    A user (typically a consultant or contractor) can be a member of several customer organisations on Hovermarks. The org switcher issues a fresh tenant-scoped session every time they switch; refresh tokens from the previous tenant are revoked on the spot, and database-level query filters guarantee no row from a different tenant is ever returned.

  • Point-in-time backup, drilled quarterly

    Azure Postgres Flexible Server with point-in-time restore (PITR) over a 7-day rolling window and geo-redundant backup replicated UK South → UK West. We don't trust untested backups. The restore drill is run every quarter against a throwaway server and the result is published to our internal disaster-recovery runbook. RTO target ~4 hours, RPO target ~1 hour.

  • Responsible disclosure

    Found something? Email [email protected]. We acknowledge reports promptly and credit researchers who would like to be named.

Reporting a vulnerability

If you've found a security issue in Hovermarks, here's how to tell us.

Email [email protected] with a clear description of the issue and the steps to reproduce it. Screenshots, request/response captures, or a short screen recording are welcomed. Use a private host you control. We don't accept attachments at the inbox.

We acknowledge every report within 1 business day and provide a fix-or-status update weekly until the issue is resolved or formally closed. Where a fix is shipped, we'll confirm the build that contains it so you can verify.

Public disclosure: please coordinate the timing with us. Our standard window is 90 days from a confirmed fix, earlier by mutual agreement, longer for active exploitation cases.

We don't currently operate a paid bug-bounty programme. Acknowledgment in our security advisories is offered for novel, high-impact findings.

Machine-readable contact details follow RFC 9116 at /.well-known/security.txt.

For US procurement

The questions your security review will ask.

Answered here so you can forward this page instead of waiting on a questionnaire response.

Where is our data stored?
Microsoft Azure UK South, a UK-sovereign datacentre, with geo-redundant backups in Azure UK West. Both are Microsoft regions. Your data does not leave those two regions in normal operation. For a US customer this is a cross-border transfer, and it operates under the UK Extension to the EU-US Data Privacy Framework together with standard contractual clauses in our DPA.
Can we get US data residency?
Yes, on request for Enterprise. The platform runs on Azure primitives that exist in US regions, so a dedicated US deployment is a provisioning exercise rather than a rebuild. Talk to us before you sign if in-country storage is a procurement requirement, so it is scoped into the contract rather than retrofitted.
Are you SOC 2 certified?
No, and we would rather say so than imply otherwise. There is no SOC 2 Type I or Type II report, no ISO 27001 certificate, and no third-party penetration test yet; commissioning an external test is on the post-GA roadmap. What exists today: multi-tenant isolation enforced at the application layer, MFA on every account on every plan, AES-256 encryption at rest and TLS 1.2+ in transit, an append-only cryptographically chained audit log, internal security reviews run at least quarterly, secrets scanning that blocks every release, and dependency scanning on every build. Our internal review reports are available under NDA.
Who are your sub-processors?
Named and published, with the region each one operates in, on the sub-processor page. Microsoft Azure carries the customer-data plane; the others cover authentication, email, payments, and the opt-in AI features. We notify customers before a new sub-processor starts processing.
Do you sign a DPA, and what does it cover?
Our Data Processing Agreement is published rather than negotiated from scratch: processing scope, sub-processor terms, security measures, deletion and return of data, audit rights, and transfer mechanisms. Enterprise customers can put a custom DPA and MSA in place.
How fast is breach notification?
Without undue delay and within 72 hours of becoming aware, per the DPA, with the nature of the incident, the data categories affected, our containment steps, and the contact point for follow-up. State-law notification duties in the US sit with you as controller; we give you what you need to meet them.
What happens to our data if we leave?
Export your asset registers, inspections, and report metadata as CSV at any time, plus a per-tenant JSON export of the whole tenant. Deletion runs soft first with a 30-day recycle bin, then hard deletion with blob cleanup and a tamper-evident ledger entry recording it happened.

Security FAQ

§ 99  Action

Stop chasing paperwork.
Start proving compliance.

Tag your first asset, run your first inspection, and pull a signed evidence pack, all on your free 30-day trial. No credit card required.

FORM HVK-CTA-01 · v05  ·  signed: hovermarks · us