Security & compliance

How InstaResolv handles access, data and control.

A plain account of what's built into the platform today, and what to ask us directly if you need it confirmed for your own compliance review.

Built into the platform

What's true today, by design

Role-based access control

Super Admin, App Admin, Project Admin and Project Participant each see only what their role permits configuration is separated from field access by design.

Project-wise data segregation

Every project's records and users are scoped independently. A user only sees the projects they've been invited to.

Approval-driven audit trail

Observations, permits and corrective actions move through defined status changes with a named approver at each step not a single flat record with no history.

Centralized configuration control

Only the Super Admin can change form templates, question banks and the master employee database field users can't alter what's being measured.

Data control

Choose how much control you keep over infrastructure

SaaS, private cloud or on-premise

If your organization needs data kept within specific infrastructure or under tighter internal governance, that's a deployment conversation not a limitation of the platform itself.

See deployment options

Where we're straightforward with you

Compliance reviews often ask for certifications and formal audit reports. Here's exactly where things stand so you're not guessing.

  • We don't publicly list specific certifications (such as ISO 27001 or SOC 2) on this page. If your evaluation requires one, tell us which and we'll confirm current status directly.
  • Data residency, backup frequency and encryption specifics are confirmed per deployment model during onboarding, not promised generically here.
  • If a formal security questionnaire or vendor risk assessment is part of your process, send it to our team early we'd rather answer it accurately than rush it after a deadline.
Handled per engagement

What we confirm directly with each customer

Data residency

Where your data is physically hosted, based on your chosen deployment model and region.

Backup & recovery

Backup frequency and recovery process, scoped to your deployment agreement.

Encryption in transit & at rest

Confirmed as part of your technical onboarding, matched to your deployment model.

Frequently asked

About security

Your organization owns its data. Details on export and portability are confirmed as part of your commercial agreement.

Talk to our team about this as part of your evaluation it's a reasonable ask and we'd rather plan for it than be surprised by it.

Data retention and deletion terms are set out in your commercial agreement ask your account contact for the specific clause if you need it in advance.

Email connect@instaresolv.com with the details we'll route it to the right person and follow up directly.

Have a security questionnaire to send us?

We'd rather answer it properly than have this page guess at it.

connect@instaresolv.com

Have specific compliance requirements?

Tell us what your evaluation needs, and we'll give you a straight answer.

Talk to our team See deployment options