Legal · Last updated September 30, 2026
Security
InstallCue is built as a focused, tenant-isolated readiness layer: expiring customer links, private proof files and an approval that always comes from a person.
Customer links
Every link carries at least 256 bits of randomness. Only a SHA-256 hash and the last four characters are stored. Links expire, can be revoked at any time and are rate-limited. A further link for the same request does not end the links sent before it; revoking the request ends all of them at once.
Tenant isolation
Every record belongs to exactly one organization. PostgreSQL Row Level Security and composite foreign keys prevent access across organizations, even in the face of application bugs.
Photos and files
Images live in private object storage with no public addresses, reachable only through short-lived signed URLs bound to the organization and the job. Uploads are checked for type and size; unattached files disappear after 24 hours.
Human approval
No photo or answer is ever approved automatically by AI. Only authorized staff can mark a site Ready; the database writes the review and the audit event in the same transaction.
Sign-in and sessions
Sessions live in HTTP-only cookies with SameSite protection. Passwords are stored only as hashes. Self-service signup requires a confirmed email address before a workspace is created.
Auditability
Sent, opened, saved, submitted, confirmed, reviewed and approved events are recorded. Retention is configurable per organization.
Reporting a vulnerability
Send security reports to support@installcue.com. We acknowledge them within five business days.