TrueViewly

Security

How TrueViewly approaches account protection, workspace permissions, payment security, API access, and operational safeguards.

Trust center

TrueViewly is built around workspace-based access, controlled billing operations, protected browser sessions, and secure payment handling. This page explains the main safeguards we use to protect customer accounts and product data.

Last updated: June 29, 2026

Security Approach

TrueViewly uses layered controls rather than relying on a single protection. We combine application-level authorization, account security, workspace permissions, payment-provider controls, audit records, and operational monitoring to reduce risk across the service.

No online service can guarantee absolute security, but we design security-sensitive workflows to limit exposure, enforce permissions consistently, and make suspicious or unauthorized activity easier to prevent, detect, and investigate.

Account Protection

Authentication-sensitive flows may use confirmed email requirements, password policy enforcement, captcha where configured, rate limiting, secure cookies, and browser-session controls. These controls help protect login, registration, password, and session-related workflows from abuse.

TrueViewly also supports concurrent browser-session controls. When a plan limits active browser sessions, a newer browser login can revoke an older active session. This helps reduce credential sharing and gives account access a clearer ownership boundary.

Workspace Permissions

Customer data and billing operations are scoped by workspace. Subscriptions, quota, reports, properties, projects, API keys, sharing, team roles, and dashboard usage are all checked against workspace access.

Workspace owners can manage billing-sensitive actions such as purchases, renewals, saved payment methods, and quota top-ups. Non-owner roles are limited by their assigned permissions. Admin-only operational actions are handled separately from customer workspace permissions.

Payment Security

Payments are processed by Stripe. TrueViewly does not store full card numbers or card security codes. Saved payment methods are represented by Stripe identifiers and are used only for supported subscription renewal, manual renewal, payment-method update, and billing flows.

Checkout and payment-method collection are designed so sensitive card entry is handled through Stripe-controlled payment components. Billing details, invoices, order records, and payment references are retained only as needed for service operation, support, accounting, and compliance.

API Key Security

API access uses API keys that are separate from browser sessions. API keys should be treated as secrets. Customers are responsible for storing keys securely, limiting access to keys, rotating keys when needed, and removing keys that are no longer used.

If you believe an API key was exposed, remove or rotate the key promptly from the product and review recent API activity for unexpected use.

Data And Report Access

Reports, properties, projects, uploads, generated PDFs, shared links, and usage records are intended to be available only to authorized users or through explicitly shared report links. Customers should share reports only with people who are allowed to view the underlying location and risk information.

Report outputs are decision-support materials. They may include addresses, coordinates, data-source findings, risk indicators, recommendations, and supporting evidence. Customers should treat report exports and shared links as business-sensitive information.

Operational Controls

TrueViewly keeps operational records for security, billing, admin actions, subscription events, quota activity, and support investigation. These records help us understand what happened, when it happened, and which account or workspace was involved.

Administrative access is restricted to authorized admin users and protected by additional security requirements. Admin actions are intended to support operations, billing review, security response, and customer assistance.

Customer Responsibilities

Customers play an important role in keeping their accounts secure. Use a strong password, protect your email account, do not share credentials, limit workspace invitations to trusted users, review API keys periodically, and remove access for users who no longer need it.

Do not send passwords, full payment card details, private keys, or unnecessary sensitive data through support requests. If sensitive information is accidentally shared, notify us so we can handle the request appropriately.

Reporting Security Concerns

Security concerns can be sent to [email protected]. Please include enough detail for us to investigate, such as the affected account, workspace, URL, report reference, approximate time, and a description of the issue.

We ask that you avoid destructive testing, privacy violations, service disruption, social engineering, spam, or attempts to access data that does not belong to you. We will review credible reports in good faith and prioritize issues based on risk and impact.