Every claim on this page describes something that is switched on today. Where a protection is partial, it says so.
Every connection is over HTTPS. Data is encrypted at rest, and credentials you give us for other services are separately encrypted in the database.
Agency separation is enforced in the data layer on every query, not page by page, and there is an automated test that walks the routes with another agency identifier to prove it.
Owner, manager and staff each get different permissions, and staff in a branch see their own branch. Tenants, landlords and contractors only ever see their own records.
Time-based one-time codes from an authenticator app, available on any account, and in use on ours.
The agency panel and the tenant, landlord and contractor portals each run on their own address with their own session, so a session cannot cross between them.
Who changed what and when is recorded for agency actions and for platform administration, and agencies can read their own audit log.
Taken daily and encrypted before they leave the server. Restores are rehearsed rather than assumed.
A file is identified by what is actually inside it, not by the name it arrives with, so a script cannot be uploaded dressed as an image.
Sign-in, uploads, emails and report generation are rate limited per customer, and a firewall sits in front of the site.
Platform data is hosted in the European Economic Area, and encrypted backups are stored in Western Europe. Transfers from the UK to the EEA are covered by the UK's adequacy regulations. Every company that touches your data is named in our sub-processor list, and we give 30 days' notice before adding another.
You can export everything, records and documents, at any time, from your own account. If you cancel, the account stays available for export for a grace period and is then permanently deleted. We do not sell your data, and we do not mine it for analytics.
If you believe you have found a vulnerability, email security{{ \App\Support\Brand::siteHost() }} with enough detail to reproduce it. We will acknowledge within one working day. Please give us a reasonable chance to fix it before telling anyone else, and do not access data belonging to anyone other than yourself while testing.
Letfold does not hold ISO 27001 or SOC 2 certification, and we are not going to imply otherwise on a marketing page. We are registered with the ICO under ZC044007, we have a DPA you can read before signing anything, and we publish exactly who processes your data. If your procurement process requires a specific certification, tell us early and we will say plainly whether we can meet it.
We will answer honestly, including when the answer is no.