Security, fraud & compliance
Verification is the point of the product, so these answers go deep: how photo fraud is detected, how media is encrypted and access-logged, whether the evidence holds up in a dispute, how long data is retained, and who owns it.
How does Virtual Inspection Pro prevent photo fraud?
Every capture is checked at the moment it is taken: server-side timestamps, GPS geofencing, device attestation, perceptual hashing against reused images, and detection of edited, AI-generated, and screen-recaptured photos.
Read answerHow is the media stored and secured?
Encrypted in transit (TLS 1.3) and at rest (AES-256), region-pinned storage, role-scoped access with SSO on Enterprise, and an audit log entry for every view, download, share, and export.
Read answerAre you SOC 2 and ISO 27001 compliant?
Our security programme is built around SOC 2 Type II and ISO 27001 controls, C2PA content provenance for captured media, and GDPR and CCPA obligations including DPAs, data residency, and deletion rights.
Read answerIs the verified media admissible for disputes or claims?
Yes. Every inspection ships with a tamper-evident audit trail — verified timestamp, GPS, device fingerprint, and integrity hash — that a third party can independently verify, exportable as a signed PDF.
Read answerDo you need consent to record a session?
Recording is off unless you enable it, and when enabled the customer sees an explicit consent prompt before capture begins. Consent, timestamp, and identity are stored with the session.
Read answerHow long is inspection data retained?
You set the retention period per workspace. Media and records are kept for as long as your policy specifies, deletion requests are honoured within statutory windows, and audit logs record every deletion.
Read answerWho owns the data?
You do. Your workspace owns every inspection, media file, template, and audit log. Export anytime as ZIP archives, JSON, or through the API — there is no lock-in.
Read answer