Skip to main content
Security and data handling

Security and data handling

The current public beta uses fictional examples only. This page separates active data flows from dormant account, file, payment and AI paths.

Handling register

Clear scope

Browser-local
Preferences and local tool state where applicable
Server/account
Uploads, reports, PDF, AI, admin, audit
Review scope
Evidence visible, judgement central
Professional boundary
Legal/cadastral decisions stay external

Local where applicable. Server/account where required.

Different tools have different handling paths. The important rule is to avoid blanket claims that are not true for every feature.

Browser-local where applicable

Some workspace preferences or tool state may be handled in the browser for features that are built that way. Users should export important work before clearing browser data or changing devices.

Server/account workflows

Account and administration functions remain server workflows. Real customer-file intake is disabled during the synthetic public beta, and AI processing is off.

During the synthetic public beta, use the bundled fictional examples only.

Data handling during public beta

  • SurveyMarkup is in public beta. Please do not upload confidential or real client data — use the synthetic sample files instead.
  • Report Reader parses .rpt / .txt in your browser; your original file is read locally and is never modified.
  • Real customer-file intake is disabled at the browser and server boundaries during the synthetic public beta.
  • Map workspace state, settings, and export history may be stored locally in your browser (for example IndexedDB) where applicable.
  • Every result is advisory and unverified — not for survey deliverables. A registered surveyor must confirm any finding before it is relied on.
  • Independent assurance such as ISO or SOC 2 is listed only when it is explicitly published; none is currently claimed.

What SurveyMarkup does and does not do

Trust starts with precise scope, not padlock marketing.

What it does

  • Organises review workflows around findings, evidence, and next actions.
  • Keeps evidence visible so users can trace a note back to its source context.
  • Helps prepare internal review notes for reports, PDFs, and exported linework.
  • Keeps qualified survey judgement central to the workflow.

What it does not do

  • Make professional decisions about legal boundaries, cadastral requirements, or coordinate correctness.
  • Replace qualified survey review or source-data checking.
  • Make legal or cadastral decisions about output suitability.
  • Accept real customer files during the synthetic public beta.

Security scope and evidence

These statements stay limited to documented controls, published policies and current product behaviour.

The security page lists only controls and independent assurance that SurveyMarkup has actually documented and published.

No absolute security claim is made; security depends on product controls, user practices, and deployment context.

Legal and cadastral conclusions remain with qualified professionals; exported files stay advisory.

Dormant account, file, payment and AI paths are listed separately from the current synthetic public workflow.

Third-party tools and subprocessors

Tools and services used to run SurveyMarkup during the public beta — listed so handling stays transparent.

Tool / ServicePurposeData handledLocation
STRATO VPSHosting for the website, application services, and database (Germany-based provider)Site traffic and account/session data; no new customer-file intake in the synthetic betaGermany (EU)
Self-hosted fontsTypography (Space Grotesk, IBM Plex) — no external font CDNNone — font files served from our own domainSame origin
First-party analyticsPseudonymous usage events — no third-party analytics processorAllowlisted public route identifiers and random per-tab session ids; no private paths, PII, or file namesOur server (same VPS)
PostgreSQL (self-hosted)Application databaseAccount and workflow-interview metadataOur VPS (Germany)
Redis (self-hosted)Session and cache storeSession tokens and ephemeral dataOur VPS (Germany)
Sentry (optional)Error diagnostics — scrubbed of file names, file contents, and survey data; active once error tracking is enabled for the deploymentTechnical error context only — browser/server details, app version and stack trace; no customer-file contentConfigured Sentry project region — must be confirmed for the active deployment
Stripe (conditional payment flows)Inactive in the synthetic public beta; a future reviewed payment path would use Stripe-hosted checkoutNone from the current public workflowStripe (global payment provider)
Selected AI provider (optional)Inactive in the synthetic public beta; supported dormant paths include Anthropic, OpenAI, Moonshot/Kimi or an operator-configured compatible endpointNone from the current public workflow; AI features are off and provider credentials are emptySelected provider region and terms — must be confirmed before enabling and may be outside Australia
CARTO basemapsDefault Map Linework style and map resources loaded directly by the browserBrowser IP/network headers plus viewport, zoom and tile requests — no uploaded file contents or drawn feature attributesCARTO delivery network
OpenStreetMapMap data/tiles loaded directly by the browser in the OpenStreetMap basemap modeBrowser IP/network headers plus viewport, zoom and tile requests — no uploaded file contents or drawn feature attributesOpenStreetMap tile infrastructure
Esri World Imagery (optional)Satellite imagery loaded directly by the browser when that basemap is selectedBrowser IP/network headers plus viewport, zoom and tile requests — no uploaded file contents or drawn feature attributesEsri delivery network
Google Maps Platform (optional)Backend-proxied map tiles, geocoding and place autocomplete when enabledTyped search or map parameters and SurveyMarkup server request metadata — no uploaded file contents; the browser does not load Google tiles directlyGoogle Maps Platform region/terms
Configured SMTP provider (optional)Transactional account, pilot, enquiry and payment emailRecipient address/name and the transactional message required for deliveryConfigured provider region — must be confirmed before enabling
Google or Microsoft OAuth (optional)Sign-in for an existing invited account; OAuth never creates an uninvited accountStandard OAuth request/response metadata and the email identity used to match the accountSelected identity-provider region/terms
Twilio Verify (optional)SMS verification when explicitly enabledPhone number and verification-delivery metadataTwilio provider region/terms
Configured S3-compatible storage (optional)Inactive real-file storage pathNone from the current public workflowConfigured storage provider and region — must be confirmed before enabling

No third-party analytics, advertising, or visitor-tracking services are active during public beta; optional error diagnostics carry scrubbed technical error reports only. Stripe, AI and customer-file storage paths are inactive in the current public workflow. CARTO, OpenStreetMap and selected Esri imagery load directly in the browser; optional Google map/search traffic is backend-proxied. Map providers receive the network and viewport/search parameters described above, not customer-file content. Use the bundled fictional demonstrations only. Full open-source attributions are available on the Third-party notices page.

Safety & scope

SurveyMarkup helps prepare and review working information. Every professional decision remains with the registered surveyor, and original data and final outputs require qualified review.

Assistance only - professional review remains required.