Security & compliance
Built to protect your data, and the people in it.
InSite holds real assessment records, photos and the access map of who can see what. We treat all of it the way an accessibility company should: token-isolated sign-in, access that narrows to a single property, media served on short-lived credentials, and a product held to the standards it measures against.
At a glance
The token never reaches the browser.
InSite's web sign-in runs through a backend-for-frontend: your browser talks to the InSite server, and the access token lives in an httpOnly cookie that JavaScript can't read. There's no token sitting in local storage for a stray script to lift. Sessions are short by default and refreshed quietly as you work, and any session can be revoked the moment a password changes.
Password policy
- 8+ characters
- An uppercase letter
- A lowercase letter
- A digit
- A special character
httpOnly, not in JavaScript
The access token is held in a server-managed httpOnly cookie, out of reach of any script running in the page.
Short access, sliding refresh
A two-hour access token, backed by a thirty-day sliding refresh that re-issues as long as you're active. Step away long enough and it simply lapses.
Version-based revoke
Changing a password bumps a session version, instantly invalidating every refresh token tied to it, so a credential change really does sign everyone out.
A real password policy
Every password must be at least eight characters and mix upper- and lower-case letters, a digit and a special character.
Everyone sees exactly what they should, and no more.
InSite is multi-tenant: each client's data is its own. Inside a client, privileges are role-based and granular (View, Create, Edit, Delete and Share) and they can be set right down to an individual property. A facilities lead can hold one building while a consultant team works across the whole portfolio, all under the same roof.
Multi-tenant by design
Every client is isolated: its properties, surveys, photos and reports belong to it alone.
Privileges down to one property
Per-property View / Create / Edit / Delete / Share, so access matches each person's real responsibility.
Photos stored securely, served on short leashes.
Assessment photos live in Azure Blob storage. The app never hands the browser a standing key to that storage. Images are reached through short-lived, scoped access tokens that expire, so a link that leaks doesn't become a permanent door.
Stored in Azure Blob
Media is kept in managed cloud storage, separate from the application database.
Short-lived, scoped access
Images are served via time-limited, scoped tokens rather than a permanent public URL or an exposed storage credential.
Aligned with the standards you're measured against.
InSite's framework is built around the rules your organization answers to: the Accessibility for Ontarians with Disabilities Act, the Accessible Canada Act, and the Web Content Accessibility Guidelines. We say aligns with, not certified. InSite gives you the record and the structure to demonstrate conformance, and your assessors apply the judgement.
Aligns with
- AODA
- Accessibility for Ontarians with Disabilities Act
- ACA
- Accessible Canada Act
- WCAG
- Web Content Accessibility Guidelines
Held to the bar it measures.
An accessibility tool that isn't accessible has missed the point. InSite is built to WCAG 2.2 AA: keyboard-navigable, properly labelled, focus-visible and respectful of reduced-motion. It's the same standard it asks of the buildings it assesses.
The platform, the field app and this website all target WCAG 2.2 AA.
Talk security with our team.
Book a demo and we'll walk through how InSite protects your data and access, answer your questions, and talk through plans that fit your portfolio.
No pressure, no auto-responders. A real conversation with the team that builds it.