← SyteIt

Security

Last updated: July 3, 2026

SyteIt is built on Google Cloud Platform and Firebase. We take reasonable measures to protect inspector and client data during our private beta.

Transport & storage

  • All public websites and APIs are served over HTTPS with HSTS.
  • Cloud data is stored in Google Cloud Storage with authenticated access controls.
  • API requests from mobile and web clients require valid Firebase ID tokens.

Authentication

We use Firebase Authentication with industry identity providers (Google, Apple on iOS). We do not store passwords for social sign-in flows.

Application security

  • Console and booking surfaces use security headers including X-Frame-Options, X-Content-Type-Options, and Referrer-Policy.
  • Admin tools (such as Founding Inspector review) are restricted by server-side allowlists.
  • Booking management links use unguessable tokens.

Subprocessors

We use vetted infrastructure and communications providers, including:

  • Google Cloud Platform & Firebase (hosting, auth, storage)
  • Google Gemini / Vertex AI (optional photo analysis)
  • Twilio SendGrid (transactional email)
  • Twilio (SMS notifications, when enabled)

See our Privacy Policy for how data is handled.

Responsible disclosure

If you believe you have found a security vulnerability, please email support@syteit.com with subject “Security disclosure.” Do not publicly disclose issues until we have had a reasonable opportunity to investigate.

We do not operate a formal bug bounty program during beta.

Your role

Keep your Google/Apple credentials secure, use device passcodes, and log out on shared computers. You control what inspection data and client information you upload.