Access and security

Simple for an invited viewer. Controlled by the inspection team.

InspectStream removes unnecessary meeting friction without making an inspection public. Viewer access is temporary, inspection-specific and separate from authenticated company access.

Implemented controls

Access is scoped to the work being performed.

These are product behaviors implemented in the current application. They are not a substitute for a formal security assessment or compliance certification.

RECEIVE_ONLY

Viewer access does not publish audio or video

Invited viewers receive the inspection stream. Their access token is not allowed to publish camera or microphone tracks into the session.

EXPIRING_LINK

Inspection links are temporary

The short viewer link has a defined expiration and is revoked when the inspector ends the inspection, rather than remaining a permanent public viewing address.

SERVER_CHECK

The short code is checked by the server

The URL contains a short inspection code, not a reusable media credential. The server checks the inspection status and expiration before issuing room access.

PRIVATE_MEDIA

Recordings and photos stay in private storage

Completed media is not intended to live at permanent public object URLs. Playback is delivered with short-lived signed access.

ORG_ACCESS

Company records are tied to organization membership

Authenticated application routes resolve the signed-in user’s organization and role before allowing access to inspections or administration functions.

ROLE_CONTROL

Administrative actions require an authorized role

Organization owners and administrators can manage their company. Platform support access is separately controlled through the deployment allowlist.

Viewer access flow

A link is convenient. It is not unrestricted access.

01 — Invitation

The inspector shares a private inspection link.

The invited person receives a short browser link through the inspector’s normal sharing workflow. They do not create an InspectStream account.

02 — Validation

The server validates the inspection before granting access.

The request is checked against the inspection record, including whether the session is still available and whether the link has expired.

03 — Scoped session

The viewer receives access to that inspection only.

The issued room credential is scoped to the inspection and configured for receive-only viewing rather than general application access.

04 — Revocation

Ending the inspection closes viewer access.

The live room closes and the viewer link is no longer usable. The organization retains the completed inspection record inside the authenticated application.

Company access

Authentication identifies the user. Membership determines the company.

A valid account alone is not treated as permission to use company inspection data. Application routes resolve organization membership and role before performing protected work.

InspectStream does not currently represent that it has completed SOC 2, ISO 27001 or another third-party certification. Those claims should only be added after the relevant audit.
01

Signed-in crew access

Crew members authenticate before creating or reviewing company inspections.

02

Organization membership

The account must be attached to a company organization before protected routes allow access.

03

Role-based administration

Owners and administrators can manage their organization; inspector access remains more limited.

04

Separate platform support access

Cross-organization platform support is controlled separately from a customer’s own roles.

Security questions

Clear answers without inflated claims.

Does a viewer need an InspectStream account?

No. Viewers use a private inspection link. Crew members and administrators use authenticated company accounts.

Can the viewer accidentally turn on their camera or microphone?

The viewer role is receive-only and is not permitted to publish camera or microphone tracks into the inspection.

Are inspection recordings public?

They are stored as private media and are served through time-limited signed access rather than a permanent public object URL.

Does InspectStream claim a formal security certification?

No certification should be assumed from this page. It documents product controls currently implemented in the application, not the completion of a third-party compliance audit.

Review the workflow

See viewer access and record retention in a live inspection.

Use one device as the inspector and another as the invited viewer to evaluate the complete access flow.