Built so your operational evidence stays defensible.
ItemStage is the system of record for chain-of-custody evidence. Security is foundational to the product, not an afterthought.
Encryption
Data encrypted in transit (TLS 1.2+) and at rest using industry-standard algorithms.
Access controls
Role-based access, scoped API tokens, and SSO available on Multi-site plans.
Backups & durability
Continuous backups with point-in-time restore for customer data.
Audit logging
Tamper-evident chain-of-custody logs for every item, stage, and export.
Why this matters for claim evidence
ItemStage holds the record you'll reach for when an adjuster questions an inventory or a customer alleges a lost item. That evidence is only as good as the security behind it — so the specifics, plainly:
Tenant isolation at the database layer
Every table is protected by Postgres row-level security (RLS) policies — your facility's items, photos, and history are isolated from every other tenant at the database itself, not just in application code.
Private photo storage
Item photos live in private storage buckets, never on public URLs. Access is authenticated and scoped to your tenant; the photos backing your claim evidence can't be enumerated or hot-linked.
Timestamps you can stand behind
Every scan, photo, checklist answer, and stage transition is recorded server-side with the acting team member. The custody timeline is append-style history — the record of what happened, when, by whom.
Your data leaves with you
Items, photos, and full history export as CSV plus complete time-stamped image archives at any time — built for high-volume facility audit trails across restoration, refurbishment, and reconditioning operations, not law-enforcement evidence workflows. Claim evidence you can't take with you isn't evidence; portability is deliberate, on every plan.
Reporting a vulnerability
If you believe you have found a security vulnerability, please email [email protected]. We respond to legitimate reports within one business day.