Security and data protection · last updated 24 September 2026
How Stavo protects the record of a job
Stavo holds the evidence of building work: stamped photographs, inspection stages, sign-offs, documents and the conversations around them. Building Control officers, SAP assessors, warranty inspectors, clients and builders each rely on it. This page sets out how that record is held and protected, plainly and without claims beyond what is true today.
- Held in private storage, encrypted in transit and at rest. The database is held in the European Union.
- Everyone sees only their part. Access is decided on our servers by the job and the person's role, for every request and every file.
- Evidence cannot be quietly removed. Every change is recorded with who made it and when, and every look is logged.
- Nobody is locked in. Each inspector can export their own log of a job, photographs included, at any time.
Where the record is held
| What | Where |
|---|---|
| The database | Accounts and the record of each job, held by Neon (PostgreSQL) in the European Union. |
| Photographs and files | Cloudflare R2 private storage. Nothing is publicly addressable; every file is served through the checks below. Confining this storage to Cloudflare's EU jurisdiction is in progress. |
| The application | Served by Cloudflare's network over HTTPS. |
| On a phone | The app keeps a copy of the part of the record that person may see, and a queue of what they did with no signal, so it works on site. Signing out clears it once the queue has been sent. The phone is never the only copy. |
Who sees what
A person sees a job only if the builder or developer running it has named them on it, by email address and in their role, and they have joined it with the job's code. Within a job, each role sees its own part:
| Role | Sees | Does not see |
|---|---|---|
| Building Control | The inspection stages, their photographs, the Building Control conversation, documents shared with them. | Quotations, payments, variations, EPC evidence, other conversations. |
| SAP assessor | The EPC evidence items and their photographs, the EPC conversation. | Building Control's stages and notes, money, other conversations. |
| Warranty inspector | The warranty stages and the photographs filed to them, the warranty conversation. | Money, EPC evidence, Building Control's notes. |
| Client | Their own job: progress, their conversation, documents shared with them, the quotation, variations and payments. | Draft variations, other jobs, conversations they are not in. |
| Builder on a developer's job | The work on that job, and their own quotation, variations and payments. | Any other builder's prices. |
These rules live in one place and run on the server for every request: what is sent to a phone is already cut down to that person's part. A file — a photograph, a document, an attachment — is served only if it is in that person's part of the record. Nobody at Stavo reads the content of a job in the course of running the service.
Accounts and sign-in
- Passwords are at least eight characters and are stored only as a salted scrypt hash, which cannot be turned back into the password.
- A session is a long random token. Only its hash is stored, so a copy of the database signs nobody in. Sessions last 30 days. On the website a session travels only in a cookie that scripts cannot read and that is sent only over HTTPS; in the store apps it is held in the app's own storage.
- Repeated attempts to sign in, sign up, reset a password or join a job are slowed, by address and by network.
- A forgotten password is reset only by a single-use link emailed to the account's address, valid for one hour. Resetting or changing a password ends every other session.
- An account can be suspended, or signed out everywhere at once, immediately.
The integrity of the evidence
- Every photograph is stamped at the moment it is taken with the date, time, map position, the accuracy of that position and who took it.
- A photograph filed as evidence, a sign-off, a signature or a message cannot be deleted by anyone through the app. It can be moved, annotated or superseded, and the earlier version remains.
- Every change to a job is recorded on the server with who made it and when.
- A whole job leaves Stavo only when it is deleted at the request of the person entitled to ask, as set out under Keeping and deleting below.
What is logged
Alongside the record of every change, Stavo keeps an access log: each sign-in and sign-out, each refused sign-in with the reason, each time a person opens a job's record or a file on it, and each report taken away — with the time and the network address. It is kept for twelve months, then deleted. It means the question "who has seen this job?" can be answered.
Protection in transit and at rest
- All traffic is encrypted with HTTPS. Browsers are told to use nothing else (HTTP Strict Transport Security).
- The database and file storage are encrypted at rest by their providers.
- Every page carries a Content Security Policy that allows scripts from Stavo alone, and the site cannot be framed by other sites.
Getting data out
- Building Control, the SAP assessor and the warranty inspector can each export their own log of a job as a PDF — every stage or item, its status, their notes and decisions, and each photograph with its date, time, position and who took it.
- The builder or developer can generate a handover pack for each home.
- A complete export of an organisation's records is provided on request.
Keeping and deleting
The record of a job is kept for as long as the job exists on Stavo. When a job or an account is deleted at the request of the person entitled to ask, it is removed from the live service within 30 days and from backups within a further 90. Records that others on the job rely on, such as a sign-off, may be exported first.
If something goes wrong
If a breach of personal data occurs, we will tell the organisations and people affected without undue delay, and report it to the Information Commissioner's Office within 72 hours where the law requires. To report a security concern, write to [email protected]; it is read and acted on promptly.
The services Stavo runs on
| Service | What it does |
|---|---|
| Cloudflare | Serves the application and the API; stores photographs and files. |
| Neon | The database, in the European Union. |
| Resend | Sends the password-reset email. |
| OpenStreetMap, postcodes.io | Map tiles behind a photograph's location and the look-up of a job's position from its address. No account or name is sent. |
| Google Fonts | The typeface on the web pages. |
For a council or other organisation, a data processing agreement setting out these terms is available on request. How personal information is handled is described in full in the privacy notice.