Assurance
Security overview
A plain statement of the controls we operate today, written by us rather than certified by anyone else. We would rather be accurate than impressive.
Last updated August 2026
Access control
Every property record belongs to one owner account. Access by anyone else — household members, a conveyancer working a matter, a trade completing a handover — exists only where the owner granted it, and is enforced at the database row level rather than in the interface alone.
Share links are tokenised, scoped to the sections you choose, carry an expiry, and can be revoked at any time. Closing a conveyancing matter withdraws the fee earner’s access automatically.
Data protection in transit and at rest
Traffic to the service is served over HTTPS. Documents are held in private storage that is not publicly listable, and are served through short-lived signed links to people who already have access to the record. Our hosting and database providers encrypt stored data at rest as part of their platform service.
Authentication
Sign-in supports email and password or Google. Passwords are hashed by our authentication provider and are never visible to us. Passwords are checked against known-breached password lists at the point they are set.
Audit and traceability
Significant actions on a record — sharing, evidence requests, matter linking and closure — are written to an append-only history that the owner can read and that cannot be edited or deleted from the application.
Backups and continuity
The database is backed up by our managed hosting provider on their standard schedule. You can export a full copy of any property record as a structured file at any time, so your record is never trapped in our service. We do not currently publish an uptime commitment or a contractual recovery time objective; if you need one for a procurement exercise, contact us and we will tell you honestly what we can and cannot sign.
What we do not claim
We hold no security certification at this stage. We are not ISO 27001 certified, not SOC 2 audited, and hold no government accreditation. Any statement to the contrary, wherever you see it, is wrong. We will publish certification status here when and if it changes.
Reporting a vulnerability
Email security@homerekkord.com with enough detail to reproduce the issue. We aim to acknowledge within two working days and to keep you informed while we investigate.
Please test only against your own account or data, avoid privacy-invasive or destructive testing, and give us reasonable time to fix an issue before disclosing it. We will not pursue legal action against researchers who follow that. We do not currently run a paid bounty.
Incidents
If a personal data breach occurs and it is likely to result in a risk to people, we will notify the Information Commissioner’s Office within 72 hours of becoming aware, and will tell affected users directly where the risk to them is high.
HomeRekkord is operated by Proja AI Ltd, a company registered in England & Wales, company number 16963746, registered office 128 City Road, London, EC1V 2NX. Written notices may be sent to hello@homerekkord.com.