Security, Privacy & Trust // Control Who Sees What

Share the property without sharing more than each audience needs.

SiteSee separates public property content from protected buyer, planning, operational and portfolio information. Your organization controls what is published, who receives access and which systems remain authoritative.

SiteSee access-control interface

Clear Responsibility From the Beginning

See exactly who controls each part of your deployment.

You can separate your authority, SiteSee-operated responsibilities and provider dependencies before information is published or connected.

01Your organization

You decide what is accurate, approved and appropriate to publish.

  • Property content and authoritative records
  • Audiences, users and internal policy
Your content and account decisions
SiteSee Spatial Link symbolShared responsibilityClear authority
02SiteSee

You receive documented controls for the service you deploy.

  • Service and account controls
  • Configuration, boundaries and documentation
The service within scope
SiteSee Spatial Link symbolVerified connectionPurpose and authority
03Connected providers

You can evaluate each connection while preserving the authoritative source.

  • Provider policies, availability and data
  • Credentials, terms and retention
The provider’s system and terms
Your control modelYou know who approves, operates and responds—and which system remains authoritative.

Purpose-Based Access

Give each audience only the property information its work requires.

You can separate public, qualified and protected views while preserving one property foundation.

SiteSee purpose-based access interface
Purpose-based access architectureQualified plannerRole lens
CapabilityViewContributeChangeGovern
Public property experienceAllowedNoNoNo
Protected planning viewAllowedNotesNoNo
Collaboration recordsAllowedAllowedOwn itemsNo
Property content and publishingAssignedNoNoNo
Operational workspaceNoNoNoNo
Users, roles and portfolio reportingNoNoNoNo
Your access principleBegin with the minimum appropriate access, review changes and keep public information separate from protected work.

Privacy Across the Data Lifecycle

Use only the information your approved purpose requires.

You decide why information is needed, who may use it, where it may be shared and when it should be reviewed or removed.

Lifecycle control path
01DefineName the purpose and affected people.

Begin with the outcome you approved.

02LimitUse only the information required.

Capability alone is not a reason to collect.

03ControlAssign access, sharing and authority.

Keep use aligned with the approved purpose.

04Review or removeKeep information only while the purpose remains valid.

Assign review, export and deletion responsibility.

Notice, consent, legal basis, retention and rights depend on the actual deployment and jurisdiction.
SiteSee privacy lifecycle interface
Data-class review
Selected data classProperty content and assets
Customer authority
Approved purposePresent the property accurately and support the buyer’s decision.
Typical informationImages, plans, video, documents, labels and spatial relationships.
VisibilityPublic, protected or users-only according to the content layer.
Retention and authorityDefined by the account, contract, lifecycle and customer policy.
Privacy questionDoes every published asset have an approved purpose, a known owner and a clearly assigned audience?

Security as an Operating Responsibility

Give your team a clear path to protect, respond and recover.

You can identify who owns each control, how relevant events are handled and how service is restored.

A review structure—not a certification.
01Own

Assign responsibility and priorities.

Clear ownership
02Protect

Match safeguards to the deployment.

Appropriate control
03Observe and respond

Define review, escalation and communication.

Prepared response
04Recover and improve

Restore service and strengthen readiness.

Continued improvement
Your assurance ruleEvery claim should match the controls, responsibilities and evidence available for your service.

Procurement and Assurance

Give your procurement team answers tied to the service you are actually buying.

Your requirements depend on the audience, information, hosting, integrations, account configuration and contract. You should be able to distinguish what is available, account-specific, planned or not claimed.

01AI-assisted workflows

Know how generated or modified property imagery is handled.

Confirm approved sources, provider handling, retention, human approval and the condition represented.

Workflow-specific review
02Connected systems

Know what each connection exchanges and who controls it.

Confirm purpose, information, credentials, authority, monitoring and revocation before connection.

Connection-specific review
SiteSee procurement assurance interface
Evidence status

Know the status behind every assurance.

A clear status helps your stakeholders evaluate the evidence available for the actual deployment.

AvailableDocumented and reviewable.Evidence exists
Account-specificDepends on service or contract.Scope required
PlannedNot yet represented as complete.Not yet a control
Not claimedNot publicly represented.No badge language
Review areaYour questionTypical status
Service and data flowWhat information moves through the service and where?Available / scoped
Hosting and providersWhich providers support delivery, storage or processing?Account-specific
Identity, roles and accessWho can access, change or govern each layer?Available / scoped
Purpose, sharing and retentionWhy is information used, shared and retained?Account-specific
Response, recovery and testingHow are controls reviewed and relevant events handled?Evidence required
Contractual and independent assuranceWhich commitments or assessments apply to your exact scope?Only if verified
Your trust boundarySiteSee does not claim absolute security, blanket regulatory compliance or certifications outside verified scope. Your policies and authoritative systems remain controlling.

No-Cost Security & Trust Readiness Audit

Clarify your requirements before security review slows the decision.

You do not need to arrive with a completed security questionnaire. We review your intended audiences, information types, access model, connected systems and assurance expectations, then identify the questions and practical scope that should come next.

This readiness audit defines deployment requirements. It is not a penetration test, certification or legal compliance assessment.