Your files are sensitive.
Their security shouldn't be optional.
Addresses, photos of the inside of homes, contracts, signatures, payments: we owe you verifiable mechanisms, and honesty about what isn't there yet. This page has both.
Infrastructure
- Encryption in transit (HTTPS) and at rest (hosting provider)
- Isolation between organizations, proven by test
- Backups managed by the hosting provider (professional plan)
- Encrypted cloud hosting — Canadian region being confirmed
Access
- Multi-factor authentication (TOTP MFA)
- Google and Microsoft sign-in
- Named, combinable roles
- Audit log of actions
- No secret keys on the client side
Sharing and integrity
- Revocable portal links
- SHA-256 hash on contracts and reports
- Invoices immutable once paid
- Retention policies (Law 25 module)
Proven, in place, not promised
Three registers, kept apart: what a test demonstrates, what is in place, what we do not claim.
| Area | Status | Detail |
|---|---|---|
| Isolation between organizations | Proven by test | PostgreSQL RLS policies; a foreign user sees 0 rows and cannot insert anything |
| Authentication | In place | TOTP MFA; Google and Microsoft sign-in |
| Secrets | In place | No secret keys on the client side |
| Traceability | In place | Audit log; SHA-256 hashes on contracts and reports; invoices immutable once paid |
| Sharing | In place | Revocable portal links |
| Encryption | In place | In transit (HTTPS) and at rest (hosting provider) |
| Software quality | In place | 44 unit tests, isolation suite, CI (type-checking, lint, build, 24 end-to-end tests), nightly test, separate staging — figures as of September 21, 2026 |
| Backups | By the host | Professional plan; no numbered RPO or RTO promised |
| Hosting | Being confirmed | Encrypted cloud; Canadian region: being confirmed |
| Law 25 | Tooled | Consents, access requests (30 days), incidents, retention, designated officer — details → |
| Certifications | None claimed | — |
What we do not promise
This list is what makes the rest credible.
- Hosting in Canada (being confirmed)
- A numbered RPO or RTO
- SOC 2 or ISO 27001 certification
- A full self-service export (on request today; planned)
- SAML SSO, a public API, connectors (planned)
- Automatic legal compliance for your business: DomiSpect provides the tools; it does not make you compliant
- "Zero incidents"
- Approval by any body (RBQ, BNQ, association, insurer)
Your data belongs to you
Clients, properties, inspections, reports, contracts, invoices: everything remains the property of your business. Each organization is isolated from the others, and that isolation is proven by test.
Export: on request from our team, today. A full self-service export is planned — not available today, no date.
Privacy Officer: reachable via the contact page. See the privacy policy and the terms of use.
A specific security question?
Ask it before you sign, not after. We answer with what is proven, what is in place and what is planned — in that order.
Pre-signature checks → · DomiSpect and Law 25 → · Integrations →
DomiSpect structures its reports according to Quebec standards and builds in pre-signature checks. The software is neither certified nor approved by the RBQ, the BNQ or ASTM International. The compliance of an inspection remains the professional responsibility of the inspector.