Security at Vistra

How we protect your data and keep the platform accountable.

Last updated: 14 September 2026

1. Introduction

At Vistra, security is a fundamental part of how we design, build, and operate our platform.

Vistra helps businesses capture, store, process, and share field documentation, including inspection records, photographs, reports, and operational information.

We use technical and organisational measures designed to protect customer information against unauthorised access, loss, misuse, alteration, and disclosure.

Security is an ongoing process. We continuously review and improve our practices as our platform, technology, and security requirements evolve. For how we handle personal information, see our Privacy Policy.

2. Security principles

Our security approach is based on the following principles:

Confidentiality

We design systems to ensure that information is accessible only to authorised users and services.

Integrity

We protect information from unauthorised modification and maintain reliable processing of customer data.

Availability

We aim to maintain dependable access to the Vistra platform while performing necessary maintenance and improvements.

Privacy by design

We consider privacy and security throughout product development, feature planning, and operational processes.

3. Data protection

Vistra applies reasonable safeguards to protect customer information. Security measures may include:

  • Secure data transmission
  • Access restrictions
  • Authentication controls
  • Infrastructure protection
  • Monitoring systems
  • Backup procedures
  • Security reviews
  • Operational controls

The exact security controls may evolve as our platform develops.

4. Data encryption

Data in transit

Vistra uses secure communication protocols designed to protect information transmitted between users and our systems. This helps reduce the risk of unauthorised interception during transmission.

Data at rest

Where supported by our infrastructure providers, stored information may be protected using encryption technologies designed to prevent unauthorised access to stored data.

5. Account security

Vistra provides account security features designed to protect user access. Security measures may include:

  • Password protection
  • Secure authentication systems
  • Session management
  • Access controls
  • Account recovery processes

Users are responsible for:

  • Maintaining secure passwords
  • Protecting account credentials
  • Limiting account access
  • Reporting suspicious activity

6. Access control

We follow access control practices designed around limiting unnecessary access to information. Access may be restricted based on:

  • User permissions
  • Business roles
  • System requirements
  • Operational responsibilities

Internal access to customer information is limited to authorised personnel and service providers who require access to perform legitimate business functions.

7. Application security

Vistra follows secure software development practices intended to reduce security risks. These practices may include:

  • Secure coding practices
  • Code reviews
  • Dependency monitoring
  • Error handling
  • Security testing
  • Vulnerability management

We aim to identify and address security issues throughout the software development lifecycle.

8. Infrastructure security

Vistra relies on secure infrastructure providers and technology partners to operate its Services. Infrastructure protections may include:

  • Network security controls
  • Access restrictions
  • Monitoring systems
  • Availability protections
  • Backup mechanisms
  • Physical security measures provided by hosting providers

9. Data backups

We maintain backup processes designed to support service reliability and data recovery. Backup practices may include:

  • Automated backups
  • Data recovery procedures
  • Storage redundancy

Backup availability and retention periods may vary depending on system requirements and service providers.

Users should maintain their own copies of critical business information.

10. Monitoring and logging

Vistra may use monitoring and logging systems to support:

  • Platform reliability
  • Security detection
  • Troubleshooting
  • Performance improvement
  • Abuse prevention

Security-related events may be reviewed to identify suspicious activity and protect the platform.

11. Vulnerability management

We aim to identify, evaluate, and address security vulnerabilities affecting Vistra. Our processes may include:

  • Monitoring security updates
  • Reviewing software dependencies
  • Investigating reported vulnerabilities
  • Applying appropriate fixes

The timing of security improvements depends on factors including severity, impact, and technical complexity.

12. Employee and contractor access

Where employees, contractors, or service providers require access to systems, we apply reasonable controls. These may include:

  • Limiting access based on responsibilities
  • Removing access when no longer required
  • Protecting confidential information
  • Following internal security practices

13. Third-party service providers

Vistra may use third-party providers to support platform operations. Examples include providers supporting:

  • Cloud infrastructure
  • Storage
  • Authentication
  • Payments
  • Analytics
  • Communication
  • AI processing

We evaluate service providers based on their ability to support reliable and secure service delivery.

Third-party providers may have their own security policies and responsibilities.

14. AI security and data processing

Vistra may use artificial intelligence features to assist users with documentation workflows. AI processing may involve tasks such as:

  • Generating descriptions
  • Improving notes
  • Organising information
  • Supporting report creation

Users should review AI-generated outputs before relying on them.

Vistra does not use AI features as a replacement for professional verification or decision-making.

AI processing practices may depend on the specific feature, provider, and technical implementation.

15. Customer responsibilities

Security is a shared responsibility. Customers are responsible for:

  • Protecting account credentials
  • Managing user permissions
  • Reviewing shared reports
  • Controlling access to uploaded information
  • Using appropriate security practices
  • Ensuring uploaded information is legally obtained

16. Incident response

Vistra maintains processes designed to identify, investigate, and respond to security incidents.

If a security incident affects customer information, we will take appropriate steps, which may include:

  • Investigating the incident
  • Containing the issue
  • Restoring affected services
  • Taking corrective actions
  • Providing notifications where legally required

17. Responsible disclosure

We encourage security researchers and users to responsibly report suspected security issues. Reports should include:

  • Description of the issue
  • Steps to reproduce
  • Potential impact
  • Relevant technical details

Please avoid:

  • Accessing other users’ data
  • Disrupting services
  • Publicly disclosing vulnerabilities before coordinated resolution

Security reports can be submitted to hello@vistra.report.

18. Compliance and standards

Vistra aims to follow reasonable security practices appropriate for a modern SaaS platform.

Specific certifications, compliance frameworks, security standards, hosting locations, or audit reports will only be claimed where they have been formally achieved or verified.

19. Security limitations

While we implement reasonable security measures, no software platform or internet service can guarantee absolute security.

Users should consider the sensitivity of information uploaded to Vistra and apply appropriate controls when handling confidential or regulated information.

20. Changes to security practices

As Vistra grows, security practices may change due to:

  • New technologies
  • Updated threats
  • Product changes
  • Operational requirements
  • Regulatory developments

Material updates may be reflected through updated documentation.

21. Contact

For security-related questions:

Questions about this policy? Contact us or email hello@vistra.report.