Security
Built so nobody has to take your word for it
A fire safety record is only worth what a sceptical reader will accept. Site Sure is designed for that reader: a client, an insurer, a residents' board or the fire authority. This page says what we do and, where we are honest about it, what we do not yet claim.
Who can get in
Accounts are created by invitation from an administrator of your organisation, never by open registration. Every person has their own account. A second factor is mandatory for every administrator and manager, with no opt-out: passkeys first, an authenticator app as the fallback, and ten single-use recovery codes shown once. Sensitive actions, such as changing someone's permissions or deleting anything, ask for the second factor again.
Passwords are checked against known breaches before they are accepted and stored only as Argon2id hashes. Sign-in attempts are bounded per address and per source. A session ends after a period of inactivity your organisation sets.
Who did what, on whose authority
Access is granted by role and scope: an organisation, a set of sites or a set of buildings, with an optional expiry. Nobody can grant a role to themselves. Covering for a colleague is a time-boxed, recorded delegation rather than a shared login, and the record shows whose authority was used for each action. A leaver is processed in one step that ends their sessions, devices, grants and delegations together.
A record that proves itself
Every change in Site Sure is an event on your organisation's audit chain. Each event is hash-linked to the one before it and the chain is append-only at the database. Every night the chain is verified and its root is published to a locked, write-once store that even the operator's own credentials cannot overwrite. The root is also served publicly, so anyone holding the events can rebuild the chain and confirm it matches. Redaction under data protection law keeps the digest and removes the content, so the chain still verifies and still shows that something was removed, and when.
Evidence that cannot be swapped
Photos and files are uploaded with a digest declared by the device that captured them. The stored object is checked against that digest before it becomes evidence. A mismatch is refused and recorded as a security event. Every record carries the time it was captured and the time the server received it, and a gap between the two beyond your organisation's tolerance is flagged rather than hidden.
Where it lives
Site Sure runs on Cloudflare. The database is in Cloudflare's Western Europe region and each organisation's data is isolated by design: every table carries the organisation's identifier and every read and write is scoped to it. Nothing is shared between organisations. Evidence files are stored separately from the database and are never held in it. Email to your people is sent through Cloudflare from an address pinned to our domain.
What we do not claim
Site Sure records what was done and when. Whether that discharges a statutory duty is a judgement for you and your appointed fire risk assessor. We do not describe the product as making anyone compliant, and we do not name a certification we do not hold. If you need a specific assurance for a client or an insurer, ask us and we will answer plainly.
Reporting a concern
If you believe you have found a security problem, please contact us and say so in the subject line. We would rather hear about it from you.