Security

The questions a customer's IT department asks us before signing, with the answer and how you can check it yourself.

Can another customer see my equipment?

Every query is filtered by the user's company. A customer cannot open another company's item, inspection round, report or document, not even by changing the number in the address: the application responds as if it did not exist. This is checked by automated tests that run with every change.

How to check it: In the cross-access tests that every version passes before it is released.

What does an operator see?

Your company administrator, operators and inspectors have different screens and permissions. An operator checks items out, returns them and looks them up; they do not see billing or account settings.

How to check it: In Operators: you add each one, change their password or remove them.

Is stealing a password enough?

Each user can turn on a code from an authenticator app or a passkey (fingerprint, face or physical key). The field app also asks for the second step from anyone who has it turned on. For sensitive actions, such as changing the email address or turning on verification, the password is requested again.

How to check it: In your profile, security section.

Will I know if someone has logged in with my account?

You see which devices your account is signed in on and close any you do not recognise. Sessions expire on their own, sign-in attempts are throttled after several failures, and a failed sign-in gives the same response whether or not the account exists.

How to check it: In your profile: My sessions and My activity.

Can anything be changed without leaving a trace?

Every creation, change and deletion of items, inspection rounds, inspections, documents and reports is recorded with who did it and when, including what is deleted. Checkouts carry the operator's signature, and photos can carry the item, the person and the time stamped on them.

How to check it: In each item's history. The full change log is kept by TTM.

Can a certificate be opened with a copied link?

Certificates, documents and signatures are kept in private storage. They have no link that can be copied: they are only delivered after checking that whoever requests them is allowed to see them.

How to check it: In each item's record, documents tab.

Do I have to give the auditor access to show them the book?

To show the inspection logbook to someone outside your company, you do not need to give them access: you send them a link that expires, that you can revoke whenever you want and that records every time it is opened.

How to check it: In each inspection round, when you send the logbook.

What if an operator loses their phone?

The session is stored in the phone's secure storage, not in an ordinary file, and the operator's account is linked to one phone. If it is lost, let us know and we unlink it: its session stops working immediately.

How to check it: In the LiftGest Campo app for Android.

What happens to my data if I leave?

You can download it whenever you want in a single file: items, inspection rounds, inspections, reports, documents, photos and movements. If you cancel, you keep access until the end of what you paid for and have 30 more days to download it; after that everything is deleted, files included. Invoices are kept for as long as the law requires.

How to check it: In My plan: Download my data.

Where are the servers and who else handles my data?

The whole connection is encrypted (HTTPS), with strict security headers, and a backup is made every day. Payments are processed by Stripe: card details do not pass through LiftGest. If you use item registration from a certificate, the document is analysed by Google's artificial intelligence service. The servers are in the European Union.

How to check it: In the privacy policy, with every provider listed.

The short answer

To paste into a security questionnaire.

Do you have a security questionnaire?

Send it to us and we will answer it point by point.

Send questionnaire