Security & privacy ยท Guide ยท updated Sep 6, 2026
Security page - Each agency's data is isolated at the database level. A user can only ever query their own agency.
- Every document view, upload, replacement and deletion is written to an audit log that admins can read and nobody can edit.
- Files are stored encrypted, served through short-lived signed links, and never through a public URL.
- iConnect credentials are encrypted at rest; sends to APD travel over SSH to a server whose identity is pinned after the first connection.
- AI features run under business associate agreements. What Coworker reads stays inside your agency.
- Support staff have no standing access to your records. When you book a screenshare, you drive.
The full security overview, including sub-processors, is on the public Security page.
Related
- Two-factor authentication and Face ID ยท Turn on an authenticator app for your login, and lock the mobile app behind Face ID.
- The audit log ยท What is recorded, how to read it, and how to export it for a surveyor.