Key takeaways
- TLS 1.3 in transit, AES-256 at rest, region-pinned storage.
- Signed short-lived URLs — no public media endpoints.
- RBAC everywhere, with SSO and SCIM on Enterprise.
- Every access is audit-logged and exportable.
Encryption end to end
All uploads travel over TLS 1.3. Files are stored with AES-256 encryption at rest in region-pinned buckets — US, EU, and Canada regions are available for data residency requirements.
Media is never served from a public URL. Every fetch uses a short-lived signed URL scoped to the requesting user.
Access scoped by workspace and role
Role-based access controls scope every action to the right team member: who can view media, who can export, who can share externally, who can administer billing.
Enterprise plans add SAML SSO and SCIM directory sync so access is revoked the moment someone leaves your directory.
External sharing that expires
Sharing an inspection outside the workspace issues a signed, expiring link rather than a copy of the file. Links can be revoked at any time, and each open is logged.
Full audit logs
Every view, download, share, and export is logged with user, timestamp, and IP address. Audit logs are exportable for compliance reviews and retained on your policy.
Operational security
Backups are encrypted and tested, access to production is least-privilege and logged, and dependencies are scanned continuously.
Keep reading
People also ask
- Can we choose where data is stored?
- Yes — US, EU, and Canada regions are available, set per workspace.
- Do you support SSO?
- SAML SSO and SCIM provisioning are included on Enterprise plans.
- Who on your side can see our media?
- Access is least-privilege and logged, and support access to customer media requires an explicit, recorded authorisation.
Need a hand with something more specific?
help@virtualinspection.ai