Security and data handling
The current public beta uses fictional examples only. This page separates active data flows from dormant account, file, payment and AI paths.
Clear scope
Local where applicable. Server/account where required.
Different tools have different handling paths. The important rule is to avoid blanket claims that are not true for every feature.
Browser-local where applicable
Some workspace preferences or tool state may be handled in the browser for features that are built that way. Users should export important work before clearing browser data or changing devices.
Server/account workflows
Account and administration functions remain server workflows. Real customer-file intake is disabled during the synthetic public beta, and AI processing is off.
Data handling during public beta
- SurveyMarkup is in public beta. Please do not upload confidential or real client data — use the synthetic sample files instead.
- Report Reader parses .rpt / .txt in your browser; your original file is read locally and is never modified.
- Real customer-file intake is disabled at the browser and server boundaries during the synthetic public beta.
- Map workspace state, settings, and export history may be stored locally in your browser (for example IndexedDB) where applicable.
- Every result is advisory and unverified — not for survey deliverables. A registered surveyor must confirm any finding before it is relied on.
- Independent assurance such as ISO or SOC 2 is listed only when it is explicitly published; none is currently claimed.
What SurveyMarkup does and does not do
Trust starts with precise scope, not padlock marketing.
What it does
- Organises review workflows around findings, evidence, and next actions.
- Keeps evidence visible so users can trace a note back to its source context.
- Helps prepare internal review notes for reports, PDFs, and exported linework.
- Keeps qualified survey judgement central to the workflow.
What it does not do
- Make professional decisions about legal boundaries, cadastral requirements, or coordinate correctness.
- Replace qualified survey review or source-data checking.
- Make legal or cadastral decisions about output suitability.
- Accept real customer files during the synthetic public beta.
Security scope and evidence
These statements stay limited to documented controls, published policies and current product behaviour.
The security page lists only controls and independent assurance that SurveyMarkup has actually documented and published.
No absolute security claim is made; security depends on product controls, user practices, and deployment context.
Legal and cadastral conclusions remain with qualified professionals; exported files stay advisory.
Dormant account, file, payment and AI paths are listed separately from the current synthetic public workflow.
Third-party tools and subprocessors
Tools and services used to run SurveyMarkup during the public beta — listed so handling stays transparent.
| Tool / Service | Purpose | Data handled | Location |
|---|---|---|---|
| STRATO VPS | Hosting for the website, application services, and database (Germany-based provider) | Site traffic and account/session data; no new customer-file intake in the synthetic beta | Germany (EU) |
| Self-hosted fonts | Typography (Space Grotesk, IBM Plex) — no external font CDN | None — font files served from our own domain | Same origin |
| First-party analytics | Pseudonymous usage events — no third-party analytics processor | Allowlisted public route identifiers and random per-tab session ids; no private paths, PII, or file names | Our server (same VPS) |
| PostgreSQL (self-hosted) | Application database | Account and workflow-interview metadata | Our VPS (Germany) |
| Redis (self-hosted) | Session and cache store | Session tokens and ephemeral data | Our VPS (Germany) |
| Sentry (optional) | Error diagnostics — scrubbed of file names, file contents, and survey data; active once error tracking is enabled for the deployment | Technical error context only — browser/server details, app version and stack trace; no customer-file content | Configured Sentry project region — must be confirmed for the active deployment |
| Stripe (conditional payment flows) | Inactive in the synthetic public beta; a future reviewed payment path would use Stripe-hosted checkout | None from the current public workflow | Stripe (global payment provider) |
| Selected AI provider (optional) | Inactive in the synthetic public beta; supported dormant paths include Anthropic, OpenAI, Moonshot/Kimi or an operator-configured compatible endpoint | None from the current public workflow; AI features are off and provider credentials are empty | Selected provider region and terms — must be confirmed before enabling and may be outside Australia |
| CARTO basemaps | Default Map Linework style and map resources loaded directly by the browser | Browser IP/network headers plus viewport, zoom and tile requests — no uploaded file contents or drawn feature attributes | CARTO delivery network |
| OpenStreetMap | Map data/tiles loaded directly by the browser in the OpenStreetMap basemap mode | Browser IP/network headers plus viewport, zoom and tile requests — no uploaded file contents or drawn feature attributes | OpenStreetMap tile infrastructure |
| Esri World Imagery (optional) | Satellite imagery loaded directly by the browser when that basemap is selected | Browser IP/network headers plus viewport, zoom and tile requests — no uploaded file contents or drawn feature attributes | Esri delivery network |
| Google Maps Platform (optional) | Backend-proxied map tiles, geocoding and place autocomplete when enabled | Typed search or map parameters and SurveyMarkup server request metadata — no uploaded file contents; the browser does not load Google tiles directly | Google Maps Platform region/terms |
| Configured SMTP provider (optional) | Transactional account, pilot, enquiry and payment email | Recipient address/name and the transactional message required for delivery | Configured provider region — must be confirmed before enabling |
| Google or Microsoft OAuth (optional) | Sign-in for an existing invited account; OAuth never creates an uninvited account | Standard OAuth request/response metadata and the email identity used to match the account | Selected identity-provider region/terms |
| Twilio Verify (optional) | SMS verification when explicitly enabled | Phone number and verification-delivery metadata | Twilio provider region/terms |
| Configured S3-compatible storage (optional) | Inactive real-file storage path | None from the current public workflow | Configured storage provider and region — must be confirmed before enabling |
No third-party analytics, advertising, or visitor-tracking services are active during public beta; optional error diagnostics carry scrubbed technical error reports only. Stripe, AI and customer-file storage paths are inactive in the current public workflow. CARTO, OpenStreetMap and selected Esri imagery load directly in the browser; optional Google map/search traffic is backend-proxied. Map providers receive the network and viewport/search parameters described above, not customer-file content. Use the bundled fictional demonstrations only. Full open-source attributions are available on the Third-party notices page.
Safety & scope
SurveyMarkup helps prepare and review working information. Every professional decision remains with the registered surveyor, and original data and final outputs require qualified review.
Assistance only - professional review remains required.