Security

You are trusting us with other people's homes.

Every claim on this page describes something that is switched on today. Where a protection is partial, it says so.

Read the DPA Sub-processors
How your data is protected

The measures in place

Encrypted in transit and at rest

Every connection is over HTTPS. Data is encrypted at rest, and credentials you give us for other services are separately encrypted in the database.

One agency cannot see another

Agency separation is enforced in the data layer on every query, not page by page, and there is an automated test that walks the routes with another agency identifier to prove it.

Roles and branch access

Owner, manager and staff each get different permissions, and staff in a branch see their own branch. Tenants, landlords and contractors only ever see their own records.

Two-factor authentication

Time-based one-time codes from an authenticator app, available on any account, and in use on ours.

Separate sign-ins per portal

The agency panel and the tenant, landlord and contractor portals each run on their own address with their own session, so a session cannot cross between them.

An audit trail

Who changed what and when is recorded for agency actions and for platform administration, and agencies can read their own audit log.

Daily encrypted backups

Taken daily and encrypted before they leave the server. Restores are rehearsed rather than assumed.

Uploads are checked by content

A file is identified by what is actually inside it, not by the name it arrives with, so a script cannot be uploaded dressed as an image.

Rate limiting and a web firewall

Sign-in, uploads, emails and report generation are rate limited per customer, and a firewall sits in front of the site.

Where your data lives

In the EEA, with UK adequacy

Platform data is hosted in the European Economic Area, and encrypted backups are stored in Western Europe. Transfers from the UK to the EEA are covered by the UK's adequacy regulations. Every company that touches your data is named in our sub-processor list, and we give 30 days' notice before adding another.

Your rights over your data

You can export everything, records and documents, at any time, from your own account. If you cancel, the account stays available for export for a grace period and is then permanently deleted. We do not sell your data, and we do not mine it for analytics.

Reporting something

If you believe you have found a vulnerability, email security{{ \App\Support\Brand::siteHost() }} with enough detail to reproduce it. We will acknowledge within one working day. Please give us a reasonable chance to fix it before telling anyone else, and do not access data belonging to anyone other than yourself while testing.

What we are not claiming

Letfold does not hold ISO 27001 or SOC 2 certification, and we are not going to imply otherwise on a marketing page. We are registered with the ICO under ZC044007, we have a DPA you can read before signing anything, and we publish exactly who processes your data. If your procurement process requires a specific certification, tell us early and we will say plainly whether we can meet it.

Questions first

Ask us anything before you move your data.

We will answer honestly, including when the answer is no.

Contact us Read the DPA