# HousingSurvey Pro — Full Agent Specification Generated at build time from every public page's on-page content (the exact prose a visitor reads — never a separate, driftable copy) plus the REST API v1 endpoint summary. For the curated overview, see https://housingsurvey.pro/llms.txt. --- ## Awaab's Law Damp & Mould Evidence Software | HousingSurvey Pro Source: https://housingsurvey.pro/ For housing associations & their contractors # The damp & mould evidence record built to stand up to the Ombudsman. HousingSurvey Pro captures geo-stamped, tamper-evident, contemporaneous evidence in the field — then delivers it straight into your case-management system by API, webhook or EDI. Built for Awaab's Law. No reports to retype. The data is the record. [Start free — no card, no call](https://portal.housingsurvey.pro) [Try the live demo](https://demo.housingsurvey.pro)[See pricing](https://housingsurvey.pro/pricing/) Self-serve end to end: sign up, invite surveyors, connect your CMS, set up SSO. You'll never have to talk to us — but you can, any time. Prefer invoicing over a card? PO numbers, BACS/bank transfer and payment terms are a normal part of how we work with housing associations and councils — [see invoice billing](https://housingsurvey.pro/pricing/#invoicing). Field surveyors, get the app Locked on completion · server-timestamped SHA-256 chained per property UK data residency · London region ## One property. One unbroken evidence timeline. Every finalized record carries the cryptographic fingerprint of the one before it. Change anything, anywhere, ever — the chain breaks and the nightly verifier raises the alarm. First inspection 12 Jan 2026 · chain #1 recordHash 71b4fdc61637… verified Follow-up visit 03 Mar 2026 · chain #2 recordHash e3a90c2b5f18… verified Works verified 21 Apr 2026 · chain #3 recordHash 9d47ab03ce62… verified prevRecordHash prevRecordHash Sealed at completion · independently re-verified every night · chain proof in every evidence bundle ## Indestructible evidence Finalized records are locked with a server-authoritative timestamp, hash-chained per property (UPRN), and protected by an append-only audit log. Edits create superseding versions — nothing is ever silently changed or deleted. ## Integrates with everything HACT-aligned REST API, signed webhooks, SFTP flat-file EDI, scheduled CSV and a Power Automate connector. Work orders flow in from your CMS; finalized evidence flows back — whichever system you run. ## One record, every surveyor In-house teams and contractors capture into one central, per-property evidence timeline — offline-first in the field, with Entra ID single sign-on and per-surveyor seats. UK data residency by construction. ## Live in an afternoon, not a procurement cycle. ### 1 · Sign up free Create your organisation in the portal — Solo plan, full engine, one surveyor seat, no card. ### 2 · Capture evidence Install the free iOS/Android app, add your surveyors, and capture geo-stamped, hash-chained records — offline if needed. ### 3 · Connect your systems Mint an API key, add a webhook, schedule EDI drops or import our Power Automate connector — all from the Integrations page. ### 4 · Scale self-serve Upgrade plans and seats with a card, switch on Entra ID SSO and SCIM provisioning yourselves. Cancel any time; keep everything. ### UK data residency Everything lives in the London cloud region — enforced in code. ### Tamper-evident Server-locked, hash-chained records; nightly integrity verification. ### App attestation App Check enforced from day one — only genuine apps reach the data. ### Your identity provider Entra ID SSO and SCIM joiner/leaver sync, configured by you. [Read the full security model →](https://housingsurvey.pro/security/) ## Awaab's Law changed the evidential bar. Fixed timescales for investigating and fixing damp and mould mean your defence is your record: who inspected, when, where, what they measured, and what happened next. HousingSurvey Pro makes that record contemporaneous, complete and provable. [Awaab's Law guide](https://housingsurvey.pro/awaabs-law/) ## Frequently asked questions ### What makes HousingSurvey Pro records defensible under Awaab's Law? Every finalized record is locked server-side with an authoritative timestamp, hash-chained to the previous record for the same property (UPRN), geo-stamped, and covered by an append-only audit log. No app or API path can alter or delete finalized evidence, and any out-of-band change — even at the infrastructure level — breaks the cryptographic chain and is detectable by our verifier. Not even we can edit history undetectably. ### Does it integrate with our housing management system (HMS) or case-management system? Yes. HousingSurvey Pro is CMS/HMS-agnostic: a HACT-aligned REST API, signed webhooks, SFTP flat-file EDI, scheduled CSV exports and a Microsoft Power Automate connector mean it connects to NEC, Civica, MRI, Aareon and virtually any other system your IT team runs. ### Can our contractors use it too? Yes. Contractor organisations work under scoped grants from the landlord: their surveyors capture evidence against your properties, and the finalized records belong to your evidence chain. ### How is it priced? Per surveyor, per month, billed to the organisation — no per-report fees and no app-store purchases. See the pricing page for tiers. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) --- ## Compare HousingSurvey Pro | HousingSurvey Pro Source: https://housingsurvey.pro/vs/ [Home](https://housingsurvey.pro/) / Compare # Compare HousingSurvey Pro. Every page below is researched directly from the other vendor's own public site — features and pricing they publish themselves, cited, including what they genuinely do well. Where a fact isn't published, we say so rather than guess. - [HousingSurvey Pro vs AwaabSafe →](https://housingsurvey.pro/vs/awaabsafe/) AwaabSafe's deadline tracking and QR tenant reporting, compared honestly with HousingSurvey Pro's full evidence-capture app and portal. - [HousingSurvey Pro vs PocketSurvey →](https://housingsurvey.pro/vs/pocketsurvey/) PocketSurvey's general-purpose survey app — including its published £125+VAT/user/month pricing — compared with a platform built specifically for housing associations. - [HousingSurvey Pro vs paper & spreadsheets →](https://housingsurvey.pro/vs/paper-and-spreadsheets/) The honest comparison most housing associations actually need: what changes, and what the real risk is, when you move off paper forms and shared spreadsheets. Third-party product and pricing details reflect what was published on each vendor's own site when these pages were researched (July 2026) and may have changed since — always verify directly with the vendor before deciding. We are not affiliated with any product named on this page. --- ## HousingSurvey Pro vs PocketSurvey | HousingSurvey Pro Source: https://housingsurvey.pro/vs/pocketsurvey/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / HousingSurvey Pro vs PocketSurvey # HousingSurvey Pro vs PocketSurvey. PocketSurvey has been a building-surveying app for years, with a Damp & Mould module aimed at Awaab's Law reporting. We reviewed its own public site and pricing page directly for this comparison — including the numbers, which PocketSurvey publishes and we've quoted rather than estimated. ## What PocketSurvey does well PocketSurvey is a genuinely mature, general-purpose survey platform: it runs across "Apple, Windows, Chromebooks, Android, iOS, iPads, iPhones" by its own description, includes an in-built App Designer and template editor so you can build custom checklists for more than just damp and mould, and its own site leads with a specific, credible time-saving claim — automating the report write-up that otherwise takes roughly three hours after a one-hour inspection. If your organisation needs one flexible surveying tool across many inspection types, not just damp and mould, that breadth is a real strength. ## Where the products differ HousingSurvey Pro PocketSurvey Built for Housing associations, councils & their contractors, specifically General building surveying across multiple sectors, customisable via templates Published pricing [Free to start, £29-£99/surveyor/month](https://housingsurvey.pro/pricing/) £125 + VAT/user/month for Damp & Mould (£25 + VAT first month) Evidence integrity Hash-chained, append-only, server-timestamped, tamper-evident by design Not published on their site — their focus is report automation, not a stated tamper-evidence model CMS/HMS integration REST API, signed webhooks, SFTP/EDI, Power Automate connector Import from Excel / export to asset-management systems, per their site Statutory clock tracking Built-in Awaab's Law clocks per work order, plus a free [deadline calculator](https://housingsurvey.pro/awaabs-law/deadline-calculator/) Not published as a distinct feature — their emphasis is automated report generation PocketSurvey details from pocketsurvey.org, including its published pricing page, reviewed for this page in July 2026. Vendor sites and prices change — verify current terms directly with PocketSurvey before deciding. ## Choose PocketSurvey if… …you need one configurable surveying app across many inspection types — not only damp and mould — and value a long-established, general-purpose platform with its own template designer. ## Choose HousingSurvey Pro if… …damp and mould evidence for Awaab's Law is the job, not one template among many — and you want tamper-evident records with the statutory clock attached automatically, flowing straight into your HMS or CMS. See [the full pricing breakdown](https://housingsurvey.pro/pricing/) or [how the evidence chain works](https://housingsurvey.pro/features/). [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### How much does PocketSurvey cost compared to HousingSurvey Pro? PocketSurvey's own pricing page lists its Damp & Mould software at £125 + VAT per user per month (after a discounted £25 + VAT first month), with volume discounts for multiple users. HousingSurvey Pro starts free and its paid tiers run £29-£99 per surveyor per month. Always check each vendor's current pricing page before deciding — published prices change. ### Is PocketSurvey built specifically for housing associations? No — PocketSurvey is a general building-surveying platform (an app designer and template editor) used across several inspection sectors, with a damp & mould module aimed partly at Awaab's Law reporting. HousingSurvey Pro is built specifically for housing associations, councils and their repairs contractors, with CMS integration (API, webhooks, EDI, SFTP) as a core feature rather than an add-on. ## More comparisons - [HousingSurvey Pro vs AwaabSafe](https://housingsurvey.pro/vs/awaabsafe/) - [HousingSurvey Pro vs paper & spreadsheets](https://housingsurvey.pro/vs/paper-and-spreadsheets/) - [The Awaab's Law deadline calculator](https://housingsurvey.pro/awaabs-law/deadline-calculator/) ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal or procurement advice. Third-party product and pricing details reflect what was published on the vendor's own site when this page was researched (July 2026) and may have changed since — always verify directly with the vendor before deciding. We are not affiliated with PocketSurvey. --- ## HousingSurvey Pro vs Paper & Spreadsheets | HousingSurvey Pro Source: https://housingsurvey.pro/vs/paper-and-spreadsheets/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / HousingSurvey Pro vs paper & spreadsheets # HousingSurvey Pro vs paper & spreadsheets. This isn't a comparison against a named competitor — it's the honest comparison most housing associations actually need, because paper forms, a shared spreadsheet, or notes typed into a CMS weeks later is the real starting point for most teams evaluating this category. No vendor claims to fact-check here, just the trade-offs. ## What paper and spreadsheets do well They're free, everyone already knows how to use them, and there's no procurement process or new login to roll out. For a very small stock or a team doing a handful of inspections a month, a well-run spreadsheet with a consistent template can genuinely work — the failure mode isn't volume, it's what happens when a record is challenged months later. ## Where the real risk sits - No tamper-evidence. A spreadsheet cell, a scanned form, a note in a CMS free-text field — any of them can be edited after the fact with no trace. That's not a hypothetical: it's precisely the kind of record the Housing Ombudsman and disrepair solicitors are trained to probe. - No enforced timestamp. A photo's EXIF data can be wrong or stripped; a spreadsheet row's "date" column is only as reliable as whoever typed it, whenever they typed it — which might not be the day of the visit. - Retyping, not recording. Field notes get typed up later, which is where detail gets lost and where the gap between "what happened" and "what got written down" opens up. - Fragile continuity. A property's evidence history is scattered across whoever's laptop the spreadsheet lives on, rather than a single append-only chain per property. ## What changes with HousingSurvey Pro The surveyor's job on site doesn't change — inspect, measure, photograph, judge. What changes is that the record is captured at the time, geo-stamped to the property, and locked with a server-set timestamp the moment it's finalised: hash-chained to the previous record for that property, so any alteration by anyone, including us, is detectable. It flows straight into your case-management system — no retyping — and exports as a signed evidence bundle when the Ombudsman or a solicitor asks for one. See [how the evidence chain works](https://housingsurvey.pro/features/). ## Choose paper & spreadsheets if… …your stock is very small, your team already has a disciplined, consistent process, and you've made a considered decision to accept the evidential risk rather than an oversight. ## Choose HousingSurvey Pro if… …you'd rather the record defend itself than rely on nobody ever having to check. Free to evaluate, no card required — see [pricing](https://housingsurvey.pro/pricing/) or try the [live demo](https://demo.housingsurvey.pro). [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### Can we just keep using paper forms and a spreadsheet for damp and mould evidence? You can, and many landlords still do today — but a spreadsheet or a scanned form has no tamper-evidence: any editable file can be changed after the fact with no trace, which is precisely what the Housing Ombudsman and disrepair claims scrutinise. A purpose-built evidence system doesn't replace your surveyor's judgement, but it timestamps and locks the record the moment it's finalised. ### What's the real risk of sticking with spreadsheets under Awaab's Law? Not the deadlines themselves — a well-run team can hit those with a spreadsheet. The risk is proving it later: a disrepair claim or Ombudsman complaint often arrives months after the event, and a record that anyone could have edited in the meantime is weaker evidence than one that was locked and hash-chained on the day. ## More comparisons - [HousingSurvey Pro vs AwaabSafe](https://housingsurvey.pro/vs/awaabsafe/) - [HousingSurvey Pro vs PocketSurvey](https://housingsurvey.pro/vs/pocketsurvey/) - [The cost of getting evidence wrong](https://housingsurvey.pro/awaabs-law/roi/) ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice, and doesn't guarantee any particular outcome for your organisation. Always confirm current statutory requirements with your compliance team. --- ## HousingSurvey Pro vs AwaabSafe | HousingSurvey Pro Source: https://housingsurvey.pro/vs/awaabsafe/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / HousingSurvey Pro vs AwaabSafe # HousingSurvey Pro vs AwaabSafe. Both products exist because of the same law. We researched AwaabSafe's own public site directly for this page — no guessing, no numbers we couldn't find published — and we'll say plainly where it does something HousingSurvey Pro doesn't, and where the two products aren't really solving the same problem. ## What AwaabSafe does well AwaabSafe is built specifically and narrowly around the Awaab's Law clock. Its own site describes automatic calculation of the statutory deadlines with UK bank holidays excluded, deadline-breach alerts before they happen, and a genuinely simple front door for tenants: one QR code per organisation , with tenants able to report a hazard in around a minute with no account or app download. That's a real, well-scoped piece of the problem, and if all you need is deadline tracking plus an easy tenant-reporting channel, it's a reasonable, purpose-built option worth evaluating directly. ## Where the products differ HousingSurvey Pro AwaabSafe Core job Field evidence capture (photos, readings, GPS) + portal + statutory clocks Deadline tracking + tenant hazard reporting via QR code Evidence integrity Hash-chained, append-only, server-timestamped, tamper-evident by design Publishes an "append-only event log" with timestamp and identity sealing Mobile field app Yes — offline-first capture app for surveyors Not published on their site — appears reporting-led rather than survey-led CMS/HMS integration REST API, signed webhooks, SFTP/EDI, Power Automate connector Not published on their site Public pricing Yes — [free to start, £29-£99/surveyor/month](https://housingsurvey.pro/pricing/) Not published on their site as of this review AwaabSafe details from awaabsafe.co.uk, reviewed for this page in July 2026. Vendor sites change — verify current claims directly with AwaabSafe before deciding. ## Choose AwaabSafe if… …your organisation's biggest gap is deadline visibility and a low-friction way for tenants to report a hazard, and you already have (or don't need) a system that captures the actual field evidence — photos, readings, inspection detail — that a written summary or an Ombudsman case needs. ## Choose HousingSurvey Pro if… …you need the evidence itself to be defensible, not just the deadline tracked: a surveyor capturing geo-stamped, tamper-evident records in the field, flowing straight into your existing housing management system (HMS) or case-management system without anyone retyping anything. See [how the evidence chain works](https://housingsurvey.pro/features/) or [the public pricing](https://housingsurvey.pro/pricing/). [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### Is AwaabSafe the same kind of product as HousingSurvey Pro? Not quite. AwaabSafe is a deadline-tracking and tenant-reporting layer — a QR code for tenants to report a hazard, and automated statutory-deadline calculation and alerts. HousingSurvey Pro is a field evidence-capture app plus management portal: surveyors record geo-stamped, tamper-evident, hash-chained evidence on site, which flows into your case-management system by API, webhook, EDI or SFTP. The two products solve adjacent but different problems. ### Does AwaabSafe publish its pricing? Not on its public site as of this review — pricing isn't listed, so we can't compare it here. HousingSurvey Pro's pricing is public: free to start, then £29-£99 per surveyor per month depending on tier. Check AwaabSafe directly for current pricing. ## More comparisons - [HousingSurvey Pro vs PocketSurvey](https://housingsurvey.pro/vs/pocketsurvey/) - [HousingSurvey Pro vs paper & spreadsheets](https://housingsurvey.pro/vs/paper-and-spreadsheets/) - [The Awaab's Law deadline calculator](https://housingsurvey.pro/awaabs-law/deadline-calculator/) ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal or procurement advice. Third-party product details reflect what was published on the vendor's own site when this page was researched (July 2026) and may have changed since — always verify directly with the vendor before deciding. We are not affiliated with AwaabSafe. --- ## Security — Tamper-Evident by Architecture | HousingSurvey Pro Source: https://housingsurvey.pro/security/ # Security HousingSurvey Pro exists to make evidence defensible, so the security model is the product. Designed against Cyber Essentials and ISO/IEC 27001 controls from the first commit (certification on the roadmap); our security design notes and DPA are available to any customer's IT team — [get in touch](https://housingsurvey.pro/contact/) (procurement/security route). For RFP-grade detail — architecture, infrastructure, our compliance mapping, evidence integrity and access control — see the [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) and the [sub-processor register](https://housingsurvey.pro/legal/subprocessors/). UK data residency, enforced in code Firestore, storage, functions and authentication run in the Google Cloud London region (europe-west2). Region pinning is written into the codebase, not a policy document. Server-authoritative finalize Completion timestamps are set by our servers. A surveyor's device clock — right or wrong, honest or not — never dates the evidence. Lock-on-Complete Finalized records have no edit or delete path for any client — surveyor, manager, admin, or our own staff accounts. Enforced by database security rules and covered by an automated test suite. Beyond that client-side lock, every sealed record is hash-chained to the one before it: any change made to a record after sealing, by any means, breaks the chain and is detected by our nightly verifier. Corrections create superseding records; originals survive. Per-property hash chains Each finalized record embeds the SHA-256 of its canonical content chained to the previous record for the same UPRN. A nightly verifier recomputes every chain and records its clean runs — absence of tampering is provable, not assumed. Append-only audit Every create, edit, finalize, export, API read, key mint and billing event is written to a hash-chained, client-unwritable audit log per organisation. App attestation (App Check) Enforced from day one: web clients attest via reCAPTCHA, iOS via App Attest, Android via Play Integrity. Scripts and tampered apps don't reach the data plane. Tenant isolation Access rides on signed custom claims minted only server-side. Contractors reach a landlord's stock only through explicit grants and work orders. Cross-tenant denial is unit-tested. Keys stored hashed, shown once API keys, SCIM tokens and webhook signing secrets are displayed once and stored only as SHA-256 hashes. Webhook payloads are HMAC-signed. Your identity provider Enterprise organisations bring Entra ID: OIDC single sign-on and SCIM joiner/leaver provisioning, configured self-serve — your directory is the source of truth for access. Minimal personal data Records describe properties, not people. Billing runs on Stripe (PCI-DSS theirs); we hold no card data. Sub-processors: Google Cloud (UK), Stripe, Ordnance Survey (address strings only). Documented security governance An internal ISMS policy set — information security, access control and a quarterly access review, incident response, business continuity and disaster recovery, data retention, and vendor management — sits behind the platform controls, with the founder as interim CISO. Alongside it we maintain a UK GDPR record of processing and a data-subject-request procedure. Mapped control by control in our compliance mapping, and shared with your procurement team on request. Responsible disclosure: report vulnerabilities to support@prosurvey.app — we acknowledge within 48 hours and don't pursue good-faith researchers. ## Questions a security reviewer actually asks ### Can HousingSurvey Pro data leave the UK? No. Firestore, Storage, Cloud Functions and Authentication are all pinned to the Google Cloud London region (europe-west2) in the codebase itself, not by policy — there is no configuration path that stores or processes tenant data outside the UK. ### Can a finalized (sealed) record be edited or deleted? Not through any client or API path, by any role, including our own staff accounts — enforced by database security rules and covered by an automated test suite. Every sealed record is also hash-chained to the one before it for its property: any change made after sealing, by any means including direct database access, breaks the chain and is detected by our nightly verifier. Not even we can edit history undetectably. Corrections create superseding records; originals survive. ### How is evidence tampering detected? Each finalized record embeds the SHA-256 hash of its canonical content, chained to the previous record for the same UPRN (property reference). A nightly verifier recomputes every chain end to end and records its clean runs, so the absence of tampering is provable, not merely assumed. ### Is HousingSurvey Pro Cyber Essentials or ISO 27001 certified? The platform is designed against Cyber Essentials and ISO/IEC 27001 controls from the first commit; formal certification is on the roadmap and not yet held. We do not claim certification we don't have — contact us for our current security design notes and DPA. ### How are API keys and webhook secrets protected? API keys, SCIM tokens and webhook signing secrets are shown once at creation and stored only as SHA-256 hashes thereafter — we cannot retrieve them either. Webhook payloads are HMAC-signed so receivers can verify authenticity. --- ## Pricing — Free to Start, Per-Surveyor Seats | HousingSurvey Pro Source: https://housingsurvey.pro/pricing/ # Pricing you can read in ten seconds. Start free, test everything, check out with a card, integrate yourselves — no sales call, no demo gate, nothing that needs us. Surveyors (field capture) are the main seat meter; office users (owner, org-admin, manager, coordinator, finance) come with a generous free bundle on every tier; viewers are always free. Annual billing = two months free , on card or invoice. ## Solo Free for evaluating in your organisation - 1 surveyor seat - 2 office users included - Viewers free (up to 3) - Full tamper-evident evidence engine - Hash-chained records & audit log - Offline capture, GPS, photo provenance - Signed evidence bundle exports [Start free](https://portal.housingsurvey.pro) ## Team £29 per surveyor / month - Everything in Solo - Unlimited surveyor seats - 5 office users included, then £6/user/mo - Viewers free & unlimited - Work orders with statutory deadlines - Contractor organisations & grants - On-brand PDF theming (colour, font, cover layout) [Start free, upgrade in-portal](https://portal.housingsurvey.pro) Most popular ## Platform £59 per surveyor / month - Everything in Team - 15 office users included, then £6/user/mo - REST API & signed webhooks - Inbound work orders from your CMS - Nightly EDI flat-file exports - SFTP file exchange with your own server - Power Automate connector [Start free, upgrade in-portal](https://portal.housingsurvey.pro) ## Enterprise £99 per surveyor / month - Everything in Platform - Unlimited office users included - Microsoft Entra ID single sign-on - SCIM automatic user provisioning - Invoice billing by default, negotiated terms - Priority support & security reviews [Talk to us](https://housingsurvey.pro/contact/) Prices in GBP. Secure Stripe checkout with itemised invoicing and promotion codes for card billing. Seat changes prorate automatically; you can never shrink below seats in use, and adding a surveyor or office user beyond your bundle prompts an upgrade — never a surprise invoice. ## How many office users do we actually get free? Housing associations and councils typically run far more office and casework staff than field surveyors — every tier includes a bundle so a normal team never pays extra. Beyond the bundle, additional office users are £6/user/month on Team and Platform; Enterprise includes them all. Solo 2 office users included · hard cap Team 5 office users included Platform 15 office users included Enterprise Unlimited office users Office users = owner, org-admin, manager, coordinator, finance. Viewer is a separate, always-free role (read-only evidence and dashboards, no create/edit/export power) — unlimited on every paid tier, capped at 3 on Solo. ## Prefer invoicing? So do most of our customers. Card self-serve is the fastest way to start, but it isn't the only way to pay. Invoice billing is a normal, first-class part of how we work with housing associations and councils — not a special favour. PO numbers — quoted on every invoice, matched to your purchase order. Agreed payment terms — 30 days as standard, negotiable for Enterprise. BACS / bank transfer — no card required anywhere in the relationship. Framework-friendly onboarding — we're used to procurement processes and due-diligence questionnaires. Team and Platform can switch to annual invoice billing any time (two months free, same as annual card). Enterprise is invoiced by default with negotiated per-seat rates and terms. Card self-serve stays available throughout — invoicing is an option, never a requirement. [Talk to us about invoicing — no card required](https://housingsurvey.pro/contact/) Independent damp or property surveyor? HousingSurvey Pro's branded PDF renderings present sealed evidence for housing organisations' own case-management systems — they're not the free-form, client-authored reports an independent surveyor writes. For that kind of report, AI report wording and everything a jobbing surveyor needs, you want our sister app [DampApp Pro](https://dampsurvey.pro). [DampApp Pro →](https://dampsurvey.pro) ## Questions a buyer actually asks ### Do I need to talk to sales? No. Create your organisation free in the portal, invite users, connect your systems and upgrade with a card — entirely self-serve on Team and Platform. Enterprise and invoice billing involve a short conversation because terms are negotiated; contact us any time you want one. ### What counts as a surveyor seat? Only active surveyors — people capturing evidence in the field app — consume surveyor seats. ### What is an office user? Owner, org-admin, manager, coordinator and finance roles are office users — the people running compliance, work orders and billing rather than capturing evidence. Each tier includes a bundle free (Solo 2, Team 5, Platform 15, Enterprise unlimited); extra office users above the bundle are £6/user/month on Team and Platform. ### Is the viewer role free? Yes — always, on every paid tier, unlimited. Viewers get read-only access to evidence and dashboards with no create/edit/export rights, so spreading visibility to stakeholders costs nothing. Solo is capped at 3 viewers. ### Is annual billing cheaper? Yes — annual is 10× the monthly price, so two months free, whether paid by card or invoice. ### Can we pay by invoice instead of card? Yes. Team and Platform can move to annual invoice billing (PO number, BACS/bank transfer, agreed payment terms) — contact us and we'll set it up; card self-serve remains available throughout. Enterprise is invoiced by default with negotiated terms. ### What happens if we cancel? You drop to the free Solo plan automatically. Every record, photo and audit trail stays intact and exportable — evidence is never held hostage. ### Is the mobile app really free? Yes. The iOS and Android apps are free to install with no in-app purchases; access is granted by your organisation and billed per surveyor seat on the web. ### Do I need a paid plan to use SFTP? Yes — SFTP is a Platform-tier feature, alongside the REST API, webhooks and EDI exports it's typically paired with. That covers connecting your own SFTP server, sending reports/letters/invoices to it, pulling in property/UPRN, SOR or tenancy data, and automatic nightly EDI-to-SFTP delivery. ### Can we put our own branding on generated PDFs? Every plan, including free Solo, puts your logo and brand colour on survey reports, works-completed packs and resident letters. Team and above additionally unlock full PDF theming — a dedicated theme colour, choice of font and cover layout — across all three document types. Set up your organisation in two minutes. [Start free — no card, no call](https://portal.housingsurvey.pro)[Talk to us about invoicing](https://housingsurvey.pro/contact/) ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) --- ## Legal & Compliance | HousingSurvey Pro Source: https://housingsurvey.pro/legal/ # Legal & compliance Everything we promise contractually, everything we tell you about how we handle your data, and the documentation behind both — in one place. ProSurvey Apps Limited (company no. 17118570), registered in England and Wales. ## Legal documents - [Terms of ServiceThe B2B SaaS agreement: service description, accounts and billing, evidence integrity, liability and governing law.](https://housingsurvey.pro/legal/terms/) - [Privacy PolicyHow we handle data: controller/processor roles, UK residency, lawful bases, retention and your UK GDPR rights.](https://housingsurvey.pro/legal/privacy/) - [Data Processing AgreementArticle 28 processor terms for customers, including our technical and organisational measures.](https://housingsurvey.pro/legal/dpa/) - [Acceptable Use PolicyWhat lawful, secure use of the Service looks like.](https://housingsurvey.pro/legal/aup/) - [Cookie NoticeThe cookies and similar technologies we use, and how to manage your consent.](https://housingsurvey.pro/legal/cookies/) - [Sub-processors & Data ResidencyThe current register of who processes data on our behalf, and where.](https://housingsurvey.pro/legal/subprocessors/) [Help centreStep-by-step guides — getting started, the management dashboard, integrations, and the mobile capture app.](https://housingsurvey.pro/legal/help/)[Trust & Security HandbookRFP-grade detail for IT and procurement: architecture, infrastructure, data protection, our compliance mapping, evidence integrity, resilience and access control.](https://housingsurvey.pro/legal/technical/) These documents are drafted to be thorough and product-accurate, but are not legal advice . Questions: [contact us](https://housingsurvey.pro/contact/). --- ## Terms of Service | HousingSurvey Pro Source: https://housingsurvey.pro/legal/terms/ [Legal & compliance](https://housingsurvey.pro/legal/) / Terms of Service # Terms of Service Version 2.4 · Effective date: 14 July 2026 · ProSurvey Apps Limited (company no. 17118570), registered in England and Wales. This document is product-accurate and drafted to be thorough, but it is not legal advice . Questions: [contact us](https://housingsurvey.pro/contact/) or email support@prosurvey.app. See also: [Privacy Policy](https://housingsurvey.pro/legal/privacy/) · [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) · [Acceptable Use Policy](https://housingsurvey.pro/legal/aup/) · [Cookie Notice](https://housingsurvey.pro/legal/cookies/) · [Sub-processors](https://housingsurvey.pro/legal/subprocessors/) Contents - [1. Definitions](#1-definitions) - [2. The Service — what it is, and what it is not](#2-the-service-what-it-is-and-what-it-is-not) - [2.1 What the Service is](#21-what-the-service-is) - [2.2 What the Service is NOT — no statutory reports, no compliance advice](#22-what-the-service-is-not-no-statutory-reports-no-compliance-advice) - [2.3 Awaab's Law and statutory deadlines — the duty stays with the landlord](#23-awaabs-law-and-statutory-deadlines-the-duty-stays-with-the-landlord) - [2.4 Evidence integrity — tamper-evident, described accurately](#24-evidence-integrity-tamper-evident-described-accurately) - [3. Accounts, organisations and Authorised Users](#3-accounts-organisations-and-authorised-users) - [4. Customer responsibilities](#4-customer-responsibilities) - [5. Plans, seats and billing](#5-plans-seats-and-billing) - [6. Customer Data and intellectual property](#6-customer-data-and-intellectual-property) - [7. Acceptable use](#7-acceptable-use) - [8. AI-assisted features — advisory drafts only](#8-ai-assisted-features-advisory-drafts-only) - [9. Availability, support and security posture](#9-availability-support-and-security-posture) - [10. Suspension and termination](#10-suspension-and-termination) - [11. Warranties, disclaimers and indemnities](#11-warranties-disclaimers-and-indemnities) - [12. Limitation of liability](#12-limitation-of-liability) - [13. Data protection](#13-data-protection) - [14. General](#14-general) These Terms of Service (the " Terms ") form the agreement between: - ProSurvey Apps Limited , a company registered in England and Wales with company number 17118570 , whose product is HousingSurvey Pro™ (" we ", " us ", " our ", the " Provider "); and - the organisation that registers for, subscribes to, or uses the Service (the " Customer ", " you ", " your "). By creating an organisation, subscribing to a paid plan, accepting these Terms in the portal or sign-up flow, or otherwise using the Service, you agree to these Terms. If you are accepting on behalf of an organisation, you warrant that you are authorised to bind that organisation. ## 1. Definitions - "Service" — the HousingSurvey Pro platform, comprising the web management portal, the iOS/Android mobile capture applications, the REST API v1, webhooks, file exports (CSV/EDI/HACT), evidence bundles, and related documentation and support. - "Evidence Record" — a survey record captured in the Service and, once finalized, sealed, hash-chained and treated as append-only. - "Customer Data" — all data the Customer or its Authorised Users submit to or generate within the Service, including Evidence Records, property data, photographs, environmental readings, work orders and audit data. - "Authorised User" — an individual (surveyor, manager, administrator, coordinator, finance user, viewer, or contractor granted access) whom the Customer permits to use the Service under its account. - "Tenant Personal Data" — personal data relating to residents, occupiers or other individuals connected to a property, processed by us on the Customer's behalf. The Customer is the controller of Tenant Personal Data; we are its processor. The [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) governs this relationship. - "Order" — the plan selection, seat counts, add-ons, and any signed order form, quotation or purchase order agreed between the parties. - "Fees" — the charges payable for the Service under the applicable Order. ## 2. The Service — what it is, and what it is not ### 2.1 What the Service is HousingSurvey Pro is an offline-first damp & mould evidence platform for UK housing associations, councils and their contractors. Its purpose is to capture, preserve and transmit contemporaneous, tamper-evident property-condition evidence. The data is the record : a finalized Evidence Record — server timestamped, geo-stamped, hash-chained per property (UPRN), and backed by an append-only audit log — is the deliverable. ### 2.2 What the Service is NOT — no statutory reports, no compliance advice The Service does not produce formal or statutory reports, and its document outputs must never be treated as such. The Service does generate document renderings of finalized Evidence Records — survey evidence reports, works-completion packs and resident letters — as presentations of the evidence you captured. These renderings, and any narrative summaries, drafts or templates the Service offers (including AI-assisted drafts under clause 8), are working aids only: they are not statutory reports, certificates, professional opinions, legal determinations, or documents intended to discharge a regulatory obligation, and you must not rely on them as any of those things. It is your responsibility to prepare, review, approve and issue any report, summary or statutory communication a law, regulator, contract or tenant requires. The Service does not provide legal, surveying, valuation, health-and-safety or compliance advice. Ratings and analyses in the Service (including HHSRS, condensation, psychrometric and indoor-air-quality outputs) are decision-support tools computed from the judgements the Authorised User enters. They are advisory and are not a local-authority determination or a statement of legal compliance. Professional judgement remains that of the assessor and the Customer. ### 2.3 Awaab's Law and statutory deadlines — the duty stays with the landlord The Service can compute and track working-day deadlines associated with Awaab's Law and similar statutory timescales, and can log warnings, notifications and audit events as those deadlines approach or pass. These are tracking and reminder tools only. The statutory duty — to investigate, to provide written summaries, to carry out works within the applicable timescales, and to comply with Awaab's Law and all other legal obligations — remains at all times the Customer's (and, where the Customer is a contractor, the landlord's). The Service is a tool that assists you in managing those obligations; it is not a guarantor of compliance, and using it does not discharge, transfer or reduce your legal duty. You acknowledge that: - deadline calculations depend on the data you enter (dates, hazard severity, stage timestamps) and on assumptions the Service makes (for example, an interpretation of "working day" as an English weekday excluding English bank holidays), which may not match your circumstances or a court's or ombudsman's interpretation; - the regulatory framework changes (for example, phased commencement of hazard scope), and while we endeavour to keep the Service current, we do not warrant that it always reflects the law in force; - notifications may be delayed, missed or not delivered for reasons within or outside our control (connectivity, device configuration, your notification settings); and - you must not rely solely on the Service's alerts to meet a statutory deadline. We are not liable for any regulatory finding, enforcement action, fine, ombudsman determination, disrepair claim, or other loss arising from a failure to meet a statutory obligation, however caused. ### 2.4 Evidence integrity — tamper-evident, described accurately Finalized Evidence Records are tamper-evident , not tamper-proof, and we describe that precisely rather than overclaiming. Neither you nor we have any application or API path to edit or delete finalized Evidence Records. Every sealed record is chained to the one before it for its property, so any change made to a record after sealing — by any means, including direct database access — alters its hash, breaks the chain, and is detected automatically by our integrity verifier and independently checkable in the evidence bundle we provide you. We do not claim that a record can never be altered or deleted at the infrastructure layer. We (as the operator of the underlying cloud project) retain administrative access to the database for operational and recovery purposes; what the Service guarantees is that any such change cannot be made undetectably . Corrections are made by superseding records; the original remains and the chain records the change. You acknowledge this tamper-evident, hash-chained design is a core feature of the Service, not a defect, and that soft-deleted drafts leave audit tombstones. ## 3. Accounts, organisations and Authorised Users 3.1 An individual may create an account and found an organisation self-serve (the mobile apps are free to install; see clause 5). The person who creates an organisation is its first administrator and warrants they are authorised to bind that organisation. 3.2 You are responsible for: the Authorised Users you invite; the roles and permissions you grant; the accuracy of the data your Authorised Users enter; and all activity under your account. You must keep credentials (passwords, passkeys, API keys, SCIM tokens, webhook secrets, SSO configuration) confidential and secure, and notify us promptly of any suspected compromise. 3.3 We require two-factor authentication (TOTP or passkey) for account tiers as configured in the Service, and offer SSO/SCIM on eligible plans. You are responsible for provisioning and de-provisioning your Authorised Users, including through your own identity provider where SSO is used. 3.4 Contractor access to a landlord organisation's data is available only via an explicit grant from the landlord organisation and is scoped by that grant. A contractor is an Authorised User of the granting organisation for the purposes of these Terms in respect of the granted data. ## 4. Customer responsibilities You agree that you will: 4.1 have and maintain a lawful basis under UK GDPR and the Data Protection Act 2018 for all personal data you (or your Authorised Users) submit to the Service, including Tenant Personal Data, and provide any required privacy information to data subjects. You are the controller of Tenant Personal Data; we process it as your processor under the DPA; 4.2 not enter special-category personal data (for example, health, ethnicity or similar) into free-text or evidence fields, and not enter more personal data than the assessment requires. Evidence Records are designed to describe properties, not people ; 4.3 ensure the accuracy of inputs — the Service's outputs (deadlines, ratings, analyses, drafts) are only as reliable as the data and judgements you enter; 4.4 secure the devices and accounts used to access the Service, apply operating-system and app updates, and use device-level protections (screen lock, disk encryption) appropriate to the sensitivity of the data; 4.5 comply with all applicable laws in your use of the Service, including housing, data-protection, health-and-safety and equality law; and 4.6 use the Service in accordance with the [Acceptable Use Policy](https://housingsurvey.pro/legal/aup/) , which forms part of these Terms. ## 5. Plans, seats and billing 5.1 The mobile apps are free to install in both app stores. There are no in-app purchases. Paid entitlements — surveyor seats, office-user add-ons, and plan features — are purchased on the web only, and provisioned through the platform's billing systems. 5.2 Metering. The Service is licensed principally per active surveyor seat on the plan tiers published on our pricing page, and, where the applicable plan so provides, per office user above the bundle included with your tier (with an add-on charge per additional office user). Viewer (read-only) access is included as described for your plan. Seat and user counts are enforced server-side. Prices exclude VAT unless stated. Current published prices are on our [pricing page](https://housingsurvey.pro/pricing/); this clause is deliberately kept meter-accurate rather than quoting specific figures, so the pricing page remains the single source of truth for numbers. 5.3 Payment channels. You may pay by either: - (a) Card / self-serve (Stripe): paid plans are billed in advance (monthly or annually) by card through our payment processor, Stripe, and renew automatically until cancelled. Card details are handled by Stripe and do not touch our systems; or - (b) Invoiced accounts (purchase order / BACS / bank transfer): eligible Customers (typically public-sector and enterprise) may request invoice billing. Where agreed, we invoice against your purchase order on agreed payment terms (for example, 30 days), payable by BACS/bank transfer. Recurring invoiced schedules renew per the Order. 5.4 Trials and pilots. We may offer free or discounted trials or pilots. At the end of a trial/pilot, or on non-payment or non-conversion, the organisation may revert to a read-only state (existing Evidence Records remain viewable and exportable, but capture and mutating actions are disabled) or to the free plan, as we notify. The free plan is provided as-is , may be fair-use limited, and has feature and capacity caps. 5.5 Changes to fees. We may change list prices with 30 days' notice, effective from your next renewal. Negotiated Order pricing is governed by the Order. 5.6 Late payment. If any undisputed sum is overdue: - we may suspend access after reasonable notice (clause 10); - statutory interest and compensation may apply. For business-to-business debts, the Late Payment of Commercial Debts (Interest) Act 1998 (as amended) may entitle us to interest, at the statutory rate (Bank of England base rate plus 8% per annum), and fixed statutory compensation on overdue sums, unless a signed Order or public-sector procurement terms state other payment terms, in which case those terms apply instead. 5.7 Taxes. Fees are exclusive of VAT and other taxes, which you will pay in addition where applicable. ## 6. Customer Data and intellectual property 6.1 Your data is yours. As between the parties, you own all Customer Data. For contractor-performed work, the finalized Evidence Record belongs to the landlord organisation that granted the work, with contractor access governed by the grant. 6.2 Licence to us. You grant us a non-exclusive licence to host, process, transmit and display Customer Data solely to provide and support the Service, to maintain evidence integrity, and as permitted by the DPA. We do not sell Customer Data, and we do not use identifiable Customer Data or Tenant Personal Data to train AI models. The public documentation assistant referenced in the [Privacy Policy](https://housingsurvey.pro/legal/privacy/) is a separate exception that uses only public marketing/documentation content, never Customer Data. 6.3 Our IP. We own and retain all rights in the Service, its software, platform, design, documentation and branding (including HousingSurvey Pro™). We grant you a non-exclusive, non-transferable, non-sublicensable licence to use the Service for your internal business purposes during the subscription term. No other rights are granted. 6.4 Feedback. If you give us feedback or suggestions, we may use them to improve the Service without obligation or restriction. 6.5 Export. Export is available on every plan while your subscription is active — via API, CSV/EDI/HACT, and signed evidence bundles — and for the export window after closure (clause 10.4). ## 7. Acceptable use Your use of the Service is subject to the [Acceptable Use Policy](https://housingsurvey.pro/legal/aup/) , incorporated by reference. In summary, you must not: use the Service unlawfully or to infringe others' rights; attempt to circumvent tenancy isolation, security rules, app attestation or seat/user enforcement; enter special-category tenant personal data into evidence fields; probe, scan or stress the Service without authorisation; or resell the Service without a written partner agreement. We may suspend API keys or access on evidence of abuse or compromise (we will tell you where practicable). ## 8. AI-assisted features — advisory drafts only 8.1 Certain features may use artificial intelligence to produce draft narrative, summaries, annotations or suggestions. All AI output is advisory, must be reviewed by a competent person before any use, and never enters the sealed evidential record automatically. You are responsible for the accuracy, appropriateness and lawfulness of anything you adopt from an AI draft. 8.2 Customer-supplied AI keys. Where survey-content AI assistance is enabled, it runs on the Customer's own AI provider account and API key (for example, Anthropic, Azure OpenAI, OpenAI, Google, or a compatible endpoint the Customer configures). We do not provide a shared or platform AI account for survey-content processing. Your use of that AI provider is governed by your own agreement and data-processing terms with that provider , and it is your responsibility to ensure that sending survey data to it is lawful and covered by an appropriate arrangement. The Service scopes each Customer's AI usage strictly to that Customer, refuses AI actions on finalized records, and fails closed when no key is configured. 8.3 The Service also offers a public documentation assistant on our website that uses our own AI arrangement; it operates only over public marketing and documentation content and never receives Customer Data or Tenant Personal Data. 8.4 We do not warrant that AI output is accurate, complete, current or fit for any purpose, and we exclude liability for reliance on AI output to the maximum extent permitted by law (subject to clause 12). ## 9. Availability, support and security posture 9.1 We provide the Service with reasonable skill and care and target high availability for the data plane, excluding scheduled maintenance (notified where practicable) and factors outside our reasonable control. The offline-first apps continue capturing during connectivity loss and sync when a connection returns. 9.2 Support is provided via our contact form or support email, with response targets varying by plan as published. 9.3 Security posture — honest, no certification claims. We operate the Service to a documented security posture, including: UK data residency (Google Cloud europe-west2, London); default-deny access rules with per-organisation isolation; server-authoritative finalization with cryptographic hash chains and append-only audit logs; app attestation; encryption in transit and at rest; and passwords held by the identity platform, with high-entropy API/SCIM bearer tokens stored only as SHA-256 digests and shown once. We do not currently hold SOC 2, ISO/IEC 27001 or Cyber Essentials certification. We describe our posture as "designed against those control frameworks and working towards certification" and make no certification claim unless and until certified. ## 10. Suspension and termination 10.1 Term. These Terms apply for as long as you have an account or an active subscription. Paid subscriptions renew automatically per the Order until cancelled. 10.2 Termination for convenience. You may cancel a subscription at any time; cancellation takes effect at the end of the current paid period, after which the organisation reverts to the free plan (or read-only, per clause 5.4). Invoiced Orders run for their committed term unless the Order provides otherwise. 10.3 Termination / suspension for cause. Either party may terminate for a material breach that is not remedied within 30 days of written notice. We may suspend access immediately where reasonably necessary for a security incident, unlawful use, a breach of the Acceptable Use Policy, or non-payment of undisputed Fees more than 14 days overdue. Where we suspend for non-payment, read-only access to your data survives for the export window so you can retrieve it. 10.4 Data after closure — export window and deletion cool-down. On closure or termination: - your data remains available for export for a defined window (self-service organisation deletion runs on a 90-day window during which the request can be cancelled in one click; account-level closure deletes account personal data within 90 days); - a superadmin-initiated organisation deletion carries its own documented cool-down before purge; - after the applicable window, Firestore and Storage data for the organisation is purged by an automated sweep, subject to any retention we are legally required or entitled to keep (for example, audit and accounting records — UK accounting records are retained for six years; see the Privacy Policy); - Evidence Records may be retained for the retention period set by the controlling organisation (default reflects housing-disrepair limitation periods) and are subject to the Article 17(3)(e) exemption where erasure of personal data within them is requested. 10.5 Survival. Clauses 2.2–2.4, 4, 6, 8.4, 10.4, 11, 12, 13 and 14 survive termination. ## 11. Warranties, disclaimers and indemnities 11.1 Our warranty. We warrant that we will provide the Service with reasonable skill and care. 11.2 Disclaimer. To the maximum extent permitted by law, and except as expressly stated in these Terms, the Service is provided "as is" and we exclude all other warranties, conditions and terms (whether express, implied or statutory), including any implied terms as to satisfactory quality, fitness for a particular purpose, and non-infringement. In particular, and without limiting clause 2, we give no warranty that use of the Service will result in compliance with any statutory obligation or produce any particular regulatory, legal or commercial outcome. 11.3 Your indemnity. You will indemnify us against losses, damages and reasonable costs (including reasonable legal fees) arising from: (a) your breach of clause 4 (Customer responsibilities) or the Acceptable Use Policy; (b) your lack of a lawful basis for, or unlawful entry of, personal data (including Tenant Personal Data or special-category data) into the Service; and (c) any third-party claim arising from Customer Data or your use of the Service in breach of these Terms, in each case subject to the limitations in clause 12. 11.4 Our IP indemnity. We will defend you against a third-party claim that the Service, as provided by us and used in accordance with these Terms, infringes that third party's UK intellectual property rights, and will indemnify you against damages and reasonable costs finally awarded against you (or agreed in settlement), provided that you: notify us promptly of the claim; give us sole control of its defence and settlement; and provide reasonable cooperation, at our expense. This indemnity does not apply to a claim arising from Customer Data, your modification of the Service, or your use of the Service in combination with materials not provided by us, and is your sole and exclusive remedy for such a claim. ## 12. Limitation of liability 12.1 Uncapped / non-excludable liability. Nothing in these Terms limits or excludes either party's liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any liability that cannot lawfully be limited or excluded. 12.2 Excluded losses. Subject to clause 12.1, neither party is liable to the other for any: indirect or consequential loss; loss of profit, revenue, anticipated savings, goodwill or business; or loss or corruption of data beyond our obligation to maintain evidence integrity and backups as described. 12.3 Liability cap. Subject to clauses 12.1 and 12.2, each party's total aggregate liability arising out of or in connection with these Terms (whether in contract, tort including negligence, breach of statutory duty, or otherwise) is limited to the total Fees paid or payable by the Customer under the Order in the 12 months immediately before the event giving rise to the claim (or, for free-plan use where no Fees are paid, £100 ). 12.4 Regulatory outcomes. Without limiting the above, we are not liable for any fine, penalty, enforcement action, ombudsman determination, disrepair award, or other loss arising from your statutory non-compliance or from your reliance on the Service to meet a statutory duty (see clause 2.3). 12.5 The parties acknowledge that the Fees reflect this allocation of risk. ## 13. Data protection 13.1 Our handling of personal data is described in the [Privacy Policy](https://housingsurvey.pro/legal/privacy/) . Where we process Tenant Personal Data on your behalf, the [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) applies and is incorporated into these Terms; the DPA prevails over these Terms on a data-protection matter (DPA clause 13.1). Each party will comply with UK data-protection law in respect of its role. 13.2 Subprocessors. We use the subprocessors listed in the DPA and Privacy Policy. We may add or replace subprocessors and will give notice of material changes as set out in the DPA, giving you the opportunity to object on reasonable data-protection grounds. ## 14. General 14.1 Entire agreement. These Terms, the Acceptable Use Policy, the Privacy Policy, the DPA, and any signed Order form the entire agreement between the parties and supersede prior discussions. In the event of conflict, a signed Order prevails over these Terms for the subject matter it addresses, and the [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) prevails over these Terms on a data-protection matter. 14.2 Changes to these Terms. We may update these Terms and will give reasonable notice of material changes to organisation administrators. Continued use after the effective date is acceptance. Material changes to the in-app legal acknowledgement wording will be reflected by a version bump in the app's legal acknowledgement in the mobile app, prompting re-acknowledgement. 14.3 Assignment. You may not assign or transfer these Terms without our consent (not unreasonably withheld). We may assign to an affiliate or successor in connection with a reorganisation, merger or sale. 14.4 Force majeure. Neither party is liable for failure or delay caused by events beyond its reasonable control. 14.5 No waiver; severance. A failure to enforce is not a waiver. If any provision is unenforceable, the rest remain in force. 14.6 Third parties. Except as expressly stated, a person who is not a party has no rights under the Contracts (Rights of Third Parties) Act 1999. 14.7 Notices. Notices to us go to our support/contact channels as published; notices to you go to your organisation administrator's registered email. 14.8 Governing law and jurisdiction. These Terms and any dispute or claim arising out of or in connection with them (including non-contractual disputes) are governed by the law of England and Wales , and the parties submit to the exclusive jurisdiction of the courts of England and Wales . ProSurvey Apps Limited · registered in England and Wales, company number 17118570 · HousingSurvey Pro™. ## Changelog - v2.4 (14 July 2026) — Full UK-law B2B SaaS suite drafted (W-E1), published live (W-E2/H-LEGAL-PUBLISH). Supersedes the v1.0 short-form page. --- ## Trust & Security Handbook | HousingSurvey Pro Source: https://housingsurvey.pro/legal/technical/ [Legal & compliance](https://housingsurvey.pro/legal/) / Trust & Security Handbook # Trust & Security Handbook For IT managers, security reviewers and procurement — the detail behind a security questionnaire or an RFP: architecture, infrastructure, data protection, our compliance mapping, evidence integrity, resilience, and access control. - [Security & Data Architecture](https://housingsurvey.pro/legal/technical/security-architecture/) - [Infrastructure & Hosting](https://housingsurvey.pro/legal/technical/infrastructure/) - [Data Protection & GDPR](https://housingsurvey.pro/legal/technical/data-protection/) - [Compliance Mapping — UK GDPR · SOC 2 · ISO/IEC 27001 · Cyber Essentials](https://housingsurvey.pro/legal/technical/compliance-mapping/) - [Evidence Integrity & Tamper Model](https://housingsurvey.pro/legal/technical/evidence-integrity/) - [Availability, Backup & Recovery](https://housingsurvey.pro/legal/technical/resilience/) - [Access Control & Permissions Model](https://housingsurvey.pro/legal/technical/access-control/) - [Sub-processors & Data Residency](https://housingsurvey.pro/legal/subprocessors/) Looking for a step-by-step product guide instead? See the [help centre](https://housingsurvey.pro/legal/help/). --- ## Security & Data Architecture | HousingSurvey Pro Source: https://housingsurvey.pro/legal/technical/security-architecture/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) / Security & Data Architecture # Security & Data Architecture ProSurvey Apps Limited (company no. 17118570) · Trust & Security Handbook Contents - [Platform summary](#platform-summary) - [Data flow, at a glance](#data-flow-at-a-glance) - [Evidence integrity (tamper-evidence)](#evidence-integrity-tamper-evidence) - [Tenant isolation & access control](#tenant-isolation-access-control) - [AI: customer-controlled, advisory-only](#ai-customer-controlled-advisory-only) - [Cryptography & secrets](#cryptography-secrets) - [Data protection & subject rights](#data-protection-subject-rights) - [Compliance posture](#compliance-posture) - [Hosting & residency](#hosting-residency) Audience: IT managers, security reviewers, procurement. This page answers the core security-questionnaire questions. Deeper topics link out to their own pages in the [Technical & Trust Portal](https://housingsurvey.pro/legal/technical/). ## Platform summary HousingSurvey Pro is a multi-tenant SaaS for UK housing associations and their contractors: a management dashboard (web) and a mobile capture app (iOS/Android via Capacitor), sharing one backend. Each customer is a tenant (an "organisation"); a landlord organisation owns its evidence, and contractor organisations perform work against it under scoped grants. ## Data flow, at a glance - A surveyor captures a survey in the mobile app (offline-capable). - On finalisation the record is sealed : cryptographically hashed and chained (see below). Photos are hashed at capture with provenance metadata. - Sealed evidence syncs to the backend; the management dashboard reads it, generates branded reports, drives work orders and the Awaab's Law timeline. - Access is mediated by server-side rules and callable checks using the signed identity, live membership/role and any server-written module override. ## Evidence integrity (tamper-evidence) Every finalised survey is an append-only, hash-chained record : - Each record's canonical JSON (sorted keys, volatile fields excluded) is hashed with SHA-256 ; the hash includes the previous record's hash ( prevRecordHash ) and a monotonic chainSeq , forming a chain per data owner. - The canonicaliser exists as a byte-identical twin on client and server, guarded in CI by a parity test and a hash-canonicaliser field check, so a record sealed on-device verifies identically on the backend. - Photos are SHA-256-hashed at capture and carry provenance (EXIF timestamp preferred over device clock; camera make/model recorded). - Tampering is detectable, not silently correctable : a verifier recomputes the chain; a broken link quarantines the record (display-metadata only, excluded from the hash) and raises an audit event and org notification. Bytes are never modified — disclosure beats concealment. If a chain-verification mismatch is detected, we follow a documented internal incident procedure to investigate and remediate. - Report versioning rides this chain: editing a sealed report creates a new sealed version linked to its predecessor, so history is ordered and every prior version is retained and independently retrievable. ## Tenant isolation & access control - Every document is scoped to an organisation. Signed claims establish the presented tenant context, while Firestore and Storage rules require an active member whose current role still matches it. Cross-tenant reads are denied at the data layer, not just the UI. - Eight organisation roles provide backwards-compatible module baselines. Sparse per-member None/View/Edit/Module-admin overrides are live, server-written and immediately evaluated by callables and rules. They cannot create owner/platform power or weaken sealed-record constraints (see [Access Control & Permissions](https://housingsurvey.pro/legal/technical/access-control/)). - Surveyor/operative evidence, property, work-order and scheduling permissions stay assignment-scoped even when upgraded. Explicit administrative and non-record grants may be organisation-scoped. - Evidence images use assignment-bearing survey/work-order paths. Storage rules resolve the linked record, allow only append-only image creates within the effective level/scope, and deny new writes to legacy paths that cannot prove assignment. Evidence bundles remain client-inaccessible. - Licensed data (e.g. the Schedule of Rates catalogue) is tenant-private and proven isolated by emulator rules tests in CI. - Privileged surfaces (members, audit events, API keys, billing, org private secrets) are server-write-only — clients cannot write them even as admin. ## AI: customer-controlled, advisory-only - AI features run on the customer's own per-tenant provider key (Anthropic/ OpenAI/Azure/Gemini/BYO). There is no shared platform key; with no key configured, AI features fail closed . - AI output is advisory and drafts-only — it never auto-enters evidence. Assessments (HHSRS, condensation, IAQ) are computed by deterministic domain engines, not by a model. ## Cryptography & secrets - In transit: TLS to all endpoints. - At rest: managed encryption via the cloud platform (Firestore/Storage). - Passwords: never stored or logged by the application; authentication is delegated to the identity platform. Non-email field logins are provisioned by a tenant admin and backed by the same identity platform (see [Access control](https://housingsurvey.pro/legal/technical/access-control/)). - Secrets (e.g. external register keys) are held in the managed secret store and injected server-side only; never shipped to clients. - App Check attests app/web clients (reCAPTCHA Enterprise on web; App Attest / Play Integrity on native builds). It is enforced across the production data plane; nonprod is deliberately monitor-only. ## Data protection & subject rights - GDPR: subject-access/full-organisation export and authorised, audited, cooldown-gated deletion are implemented. An Art. 30 Record of Processing Activities and a DSAR-handling procedure are maintained; a customer-admin per-organisation evidence-retention setting remains planned. See [Data Protection & GDPR](https://housingsurvey.pro/legal/technical/data-protection/). - Remote control: an admin can revoke a surveyor's sessions/tokens (remote logout) from the dashboard. - Auditing: privileged and destructive actions are recorded as immutable audit events. ## Compliance posture Controls are mapped to UK GDPR, SOC 2, ISO/IEC 27001 and Cyber Essentials in [Compliance Mapping](https://housingsurvey.pro/legal/technical/compliance-mapping/). The register distinguishes implemented, partial and planned controls and explicitly records that no SOC 2, ISO/IEC 27001 or Cyber Essentials assurance/certification is currently held. An internal ISMS policy set — information security, access control and a quarterly access-review procedure, incident response, business continuity/DR, data retention and disposal, vendor management, and internal acceptable use, with the founder as interim CISO — backs these controls and is shared with procurement and auditors on request. ## Hosting & residency Runs on Google Cloud / Firebase; primary region europe-west2 (London) . Subprocessors and residency detail: [Subprocessor Register](https://housingsurvey.pro/legal/subprocessors/). Status: living document. Sections marked in progress are tracked on our internal roadmap; this page is updated as those land so it never overstates the platform's current posture. [← Back to trust & security handbook](https://housingsurvey.pro/legal/technical/) --- ## Availability, Backup & Recovery | HousingSurvey Pro Source: https://housingsurvey.pro/legal/technical/resilience/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) / Availability, Backup & Recovery # Availability, Backup & Recovery ProSurvey Apps Limited (company no. 17118570) · Trust & Security Handbook Contents - [Availability model](#availability-model) - [Durability & backups](#durability-backups) - [Recovery objectives](#recovery-objectives) - [Monitoring & incident response](#monitoring-incident-response) - [Change safety](#change-safety) - [Business continuity](#business-continuity) Audience: IT/operations reviewers, procurement. Describes how HousingSurvey Pro stays available and how data is protected against loss. Items not yet formalised are marked planned / in progress — this page does not claim guarantees the platform has not yet committed to. Tracked on our internal roadmap. ## Availability model - Serverless architecture on Google Cloud / Firebase: no customer-managed servers to fail or patch. Compute (Cloud Functions) and data (Firestore, Cloud Storage) scale on the managed platform. - Offline-first capture: the mobile app is not dependent on continuous connectivity. Surveyors capture offline; finalising (sealing) and the online lookups (AI wording, EPC, weather, soil) need a connection, and sealed evidence syncs when a connection returns, so field capture is unaffected by transient outages. - Static front-ends: the dashboard and website are static assets served via CDN, decoupling their availability from backend load. ## Durability & backups - Managed durability: Firestore and Cloud Storage replicate data within the region (europe-west2) and encrypt it at rest by default. - Firestore point-in-time recovery (PITR): production has a seven-day PITR window and daily backups retained for 98 days. A nonprod drill recovered changed and deleted documents via point-in-time reads into an isolated database. The production-equivalent PITR bulk export/import and scheduled- backup restore paths remain untested, so recovery testing is partial. - Cloud Storage versioning / disaster recovery: object-versioning is enabled on Cloud Storage (evidence photos and files), with soft-delete retention and a nightly mirror to a separate versioned Archive bucket in London. The scheduled 15 July 2026 transfer succeeded. Keeping the backup in London preserves UK residency but means it is not protection against a whole-region outage; restore follows a documented internal runbook. - Evidence immutability aids recovery: because finalised records are append-only and hash-chained, a restore can be integrity-verified against the chain — corruption or gaps are detectable, not silent. ## Recovery objectives - RPO/RTO: accidental object deletion/overwrite is recoverable from live bucket versioning/soft delete with effectively no scheduled-backup gap; separate-bucket recovery has up to a 24-hour RPO. Restore took minutes at today's tiny dataset, but production-scale RTO and a regional-outage target are not tested and are not promised. ## Monitoring & incident response - Monitoring: managed platform metrics, web performance/error telemetry and integrity alerts exist. Native Crashlytics is coded but awaits the next store binary; automated nightly-backup failure alerting and a published SLO/uptime commitment are planned. - Integrity monitoring: the evidence chain verifier detects tampering or breakage and raises audit events + notifications (implemented). - Incident response: a documented internal incident procedure for evidence-tamper detections is in place, and a general incident-response plan (severity model, response lifecycle, and processor/controller breach duties) is now documented; the general-incident tabletop exercise remains planned . ## Change safety Every change is gated in CI before it can reach production — lint, unit tests with coverage floors, Firestore rules tests on the emulator, hash-canonicaliser parity checks, and full builds — reducing the risk of a change-induced outage. Release automation provides a consistent, revertible deployment path. ## Business continuity - No single-app dependency for field work: offline capture means an outage of the dashboard/backend does not stop surveyors collecting evidence. - Data portability: organisation admins can export a signed, machine- readable ZIP of the full organisation dataset, including all survey versions. Status: living document. Production PITR/backups, Storage versioning/soft delete/nightly UK backup and a limited point-in-time recovery drill are proven. Bulk/scheduled-backup recovery, production-scale RTO, regional-outage recovery, backup failure alerting and the SLO commitment remain open. [← Back to trust & security handbook](https://housingsurvey.pro/legal/technical/) --- ## Infrastructure & Hosting | HousingSurvey Pro Source: https://housingsurvey.pro/legal/technical/infrastructure/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) / Infrastructure & Hosting # Infrastructure & Hosting ProSurvey Apps Limited (company no. 17118570) · Trust & Security Handbook Contents - [Cloud platform & region](#cloud-platform-region) - [Components](#components) - [Architecture principles](#architecture-principles) - [Environments & delivery](#environments-delivery) - [Resilience & recovery](#resilience-recovery) - [Networking & access](#networking-access) - [Sub-processors](#sub-processors) Audience: IT managers, cloud/security reviewers, procurement. Describes where and how HousingSurvey Pro runs. Items not yet in production are marked planned / in progress ; this page does not describe infrastructure the platform does not have. Tracked on our internal roadmap. ## Cloud platform & region - Provider: Google Cloud Platform / Firebase. - Primary region: europe-west2 (London, UK) — Firestore, Cloud Functions and Cloud Storage are provisioned in-region for UK data residency. - CDN/edge: static app + website assets served via the platform's global CDN; data operations execute in-region. ## Components Layer Technology Notes Management dashboard (web) React + Vite SPA Served as static assets Mobile capture app React + Vite via Capacitor (iOS/Android) Offline-first; WKWebView Marketing website Astro static site Public content Database Cloud Firestore Multi-tenant; access governed by security rules Serverless backend Cloud Functions (Node 22) Callable + trigger functions; no long-running servers File storage Cloud Storage Photos + report/evidence bundles; in-region Authentication Firebase Auth / Identity Platform Email, SSO (Entra ID), tenant username-alias logins Client attestation App Check reCAPTCHA (web), App Attest (iOS), Play Integrity (Android) Secrets Cloud Secret Manager Server-side only ## Architecture principles - Serverless, no managed VMs to patch — reduces attack surface and operational burden; scaling is handled by the platform. - Multi-tenant with database-enforced isolation — every record is organisation-scoped; Firestore security rules deny cross-tenant access independently of the UI. Covered by emulator rules tests in CI. - Offline-first capture — the mobile app records surveys without connectivity and syncs sealed, hash-chained evidence when back online. - Evidence at rest is immutable — finalised records are append-only and chained; see [Security & data architecture](https://housingsurvey.pro/legal/technical/security-architecture/). ## Environments & delivery - Environments: production; a non-production/staging project is provisioned separately (secrets injected per-environment; no shared credentials). (Full non-prod parity: in progress.) - CI/CD: every change runs lint, unit tests with coverage floors, Firestore rules tests on the emulator, hash-canonicaliser parity checks and builds for all apps. Production deployment depends on CI plus the protected production environment. Hosting bundle-identity assertions and predeploy hooks block prod/nonprod asset mix-ups. - Configuration: client build-time config uses per-environment values; real secrets are never shipped to clients and are injected server-side. ## Resilience & recovery - Managed durability: Firestore and Cloud Storage provide replicated, encrypted-at-rest storage within the region. - Firestore point-in-time recovery (PITR): production has seven-day PITR plus daily 98-day backups. A limited nonprod point-in-time-read recovery drill succeeded; the production-equivalent bulk and backup restore paths remain untested. - Cloud Storage versioning / disaster recovery: both evidence buckets have versioning, 14-day soft delete and a 30-day noncurrent-version lifecycle. Production mirrors nightly to a separate versioned Archive bucket in London. This protects object/bucket loss while preserving UK residency, but the same- region design does not cover a whole-London-region outage. - Availability monitoring & SLOs: platform monitoring is in place; a published SLO/uptime commitment is planned . ## Networking & access - All client↔backend traffic is over TLS . - No inbound network access to a database or server is exposed; clients reach data only through authenticated, rules-checked SDK calls and callable functions. - Administrative access to the cloud project is restricted to the operating team under least-privilege IAM. (Access review cadence: planned.) ## Sub-processors The cloud platform (Google Cloud/Firebase) is the primary subprocessor. Any email or AI providers are enabled by the customer with their own keys , so that processing occurs under the customer's own agreements. The maintained [Subprocessor Register](https://housingsurvey.pro/legal/subprocessors/) documents each provider, purpose and transfer/residency position. Status: living document, updated as environments, monitoring and recovery drills are formalised. Where this page says planned , it means not yet in production — not a claim. [← Back to trust & security handbook](https://housingsurvey.pro/legal/technical/) --- ## Evidence Integrity & Tamper Model | HousingSurvey Pro Source: https://housingsurvey.pro/legal/technical/evidence-integrity/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) / Evidence Integrity & Tamper Model # Evidence Integrity & Tamper Model ProSurvey Apps Limited (company no. 17118570) · Trust & Security Handbook Contents - [Why it matters](#why-it-matters) - [How it works](#how-it-works) - [Sealing](#sealing) - [Chaining](#chaining) - [Client/server twin](#clientserver-twin) - [Photo provenance](#photo-provenance) - [Detection & response](#detection-response) - [What this gives a customer](#what-this-gives-a-customer) - [Limits (stated honestly)](#limits-stated-honestly) Audience: security reviewers, ombudsman/regulatory readers, procurement. This is the platform's defining differentiator: survey evidence is tamper- evident and append-only , so a report can be trusted as a contemporaneous record. The operational response detail lives in a documented internal incident procedure; this page explains the model. ## Why it matters Damp-and-mould evidence in social housing may be scrutinised by the Housing Ombudsman, regulators, or a court. A record that could have been quietly edited after the fact has little evidential weight. HousingSurvey Pro is built so that a finalised survey cannot be silently altered , and any attempt is detectable . The precise claim, stated honestly: no client app, API, webhook, or other product surface has any path to edit or delete a sealed record — that is enforced in server-side security rules and covered by an automated test suite. Beyond that, database-owner-level access (the Firebase/GCP console, or a direct Admin SDK call) is a separate trust boundary that database security rules do not — and cannot — restrict; a cloud project owner can act directly on the underlying data store. HousingSurvey Pro does not claim otherwise. What the hash chain guarantees is that any such change, from any actor, by any means, is detectable : altering or removing a sealed record changes its hash, which breaks the chain for every later record on that property, and is caught by the nightly chain verifier and by independent verification of an exported evidence bundle. The honest claim is tamper-evident , not "impossible to touch" — and that is what gives the record its evidential weight: not that access is physically prevented at every layer, but that tampering cannot be hidden. ## How it works ### Sealing When a surveyor finalises a survey, it is sealed : - The record's content is reduced to a canonical JSON form — keys sorted, volatile/display-only fields excluded — so the same content always produces the same bytes. - That canonical form is hashed with SHA-256 . The hash incorporates the previous record's hash ( prevRecordHash ) and a monotonic chainSeq , linking records into a chain per data owner. - Finalisation fields (the hashes, chain sequence, sealed timestamp) are set server-side — a client cannot forge them. ### Chaining Because each record's hash depends on the one before it, the sealed records form a chain. Altering any earlier record changes its hash, which breaks every link after it — so tampering cannot be hidden by editing a single record. ### Client/server twin The canonicaliser exists as a byte-identical twin on the client and the server. A record sealed on a surveyor's device verifies to the same hash on the backend. This parity is guarded in CI by a dedicated test and a field-level canonicaliser check, so the two implementations cannot silently diverge. ### Photo provenance Photos are SHA-256-hashed at the moment of capture and carry provenance metadata — the EXIF capture timestamp is preferred over the device clock, and the camera make/model is recorded. The hash anchors the image to the record. ## Detection & response - A chain verifier recomputes the chain and compares hashes. - A broken or mismatched link quarantines the affected record — its display metadata is flagged, but the underlying bytes are never modified (the quarantine flag itself is excluded from the hash so it cannot alter what it marks) — and raises an audit event and an organisation notification . - The guiding principle is disclosure over concealment : a tamper signal is surfaced and recorded, not silently corrected. The full triage classes, comms templates, and ombudsman-safe wording are in the incident runbook. ## What this gives a customer - Defensible records for ombudsman/regulatory scrutiny. - Report versioning without loss: an authorised edit creates a new sealed version chained to the original; the original remains intact and retrievable, so the full history is preserved and auditable (see report versioning). - Independent verifiability: because the algorithm is deterministic and documented, a third party can, in principle, recompute and check a chain. ## Limits (stated honestly) - Integrity proves a record has not changed since sealing — it does not, by itself, prove the truth of a surveyor's judgement; that rests with the qualified assessor, as the reports state. - The model protects finalised evidence; drafts remain editable until sealed, by design. Status: sealing, chaining, twin-parity, photo hashing, verifier/quarantine and sealed report versioning are implemented today . A revision creates a new sealed version; the original remains retrievable and exportable. [← Back to trust & security handbook](https://housingsurvey.pro/legal/technical/) --- ## Data Protection & GDPR | HousingSurvey Pro Source: https://housingsurvey.pro/legal/technical/data-protection/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) / Data Protection & GDPR # Data Protection & GDPR ProSurvey Apps Limited (company no. 17118570) · Trust & Security Handbook Contents - [Roles](#roles) - [What personal data is processed](#what-personal-data-is-processed) - [Data subject rights](#data-subject-rights) - [Retention & the evidence tension](#retention-the-evidence-tension) - [Security of processing (Art. 32)](#security-of-processing-art-32) - [International transfers & sub-processors](#international-transfers-sub-processors) - [Breach response](#breach-response) Audience: data protection officers, security reviewers, procurement. This page states how HousingSurvey Pro handles personal data under UK GDPR and the Data Protection Act 2018. Items not yet implemented are marked planned or in progress — this page does not claim capabilities the platform does not yet have. Tracked on our internal roadmap. ## Roles - The customer organisation (housing association / contractor) is the data controller for the personal data it processes in the platform (tenant/resident details captured during surveys, its own staff accounts). - HousingSurvey Pro is the data processor , acting on the controller's documented instructions. The published [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) governs this relationship, subject to any customer procurement/countersignature process. ## What personal data is processed Category Examples Basis Property & occupancy address, UPRN, tenure; resident-reported damp/mould controller's statutory housing duties Survey evidence photos, readings, surveyor observations, GPS at capture controller instruction Staff/surveyor accounts name, email or tenant username, role, accreditations contract / legitimate interest Audit & security logs who did what, when; sign-in events legal obligation / legitimate interest The platform is designed to minimise resident personal data: it records property condition and evidence, not resident profiles. ## Data subject rights Requests are handled under a documented DSAR procedure: for tenant/property data we act as processor and assist the customer (controller), who owns the request; for account/billing data we are controller and respond directly. The tooling behind each right: - Right of access / portability — full-organisation and subject export. Admins can export an organisation's data in a machine-readable form, including all report versions , not just the latest. The signed ZIP also includes work orders, properties, members, audit/billing data and a photo manifest; the export is audited. - Right to erasure — authorised, audited company-data deletion with a confirmation + cooldown, extending the existing organisation suspend/delete lifecycle. Personal-account deletion, a cancellable organisation-deletion window and automated purge paths are implemented. Erasure is reconciled with the evidence-retention obligation below. - Rectification — because sealed evidence is immutable, corrections are made as a new report version linked to the original (see the versioning model); the original is retained as the contemporaneous record. ## Retention & the evidence tension Housing damp-and-mould evidence may need to be retained for regulatory, ombudsman, or litigation purposes. HousingSurvey Pro reconciles this with erasure by: - keeping sealed evidence immutable and hash-chained for its retention period (set by the controller's schedule); - supporting erasure at the organisation level (offboarding) with audit; - treating corrections as new versions rather than destructive edits. Scheduled janitors enforce configured draft and organisation deletion windows and the EDI artefact retention limit. A customer-admin per-organisation evidence-retention setting remains planned; contractual retention text must not be confused with a shipping per-tenant configuration control. ## Security of processing (Art. 32) Summarised here; full detail in [Security & data architecture](https://housingsurvey.pro/legal/technical/security-architecture/): - encryption in transit (TLS) and at rest (managed); - tenant isolation enforced in server-side security rules; - role baselines plus server-evaluated per-member module levels from None to Module admin; tenant, owner, sealed-record and field-assignment boundaries cannot be overridden; - tamper-evident, hash-chained evidence with a quarantine + audit response; - customer-controlled, advisory-only AI (no shared key; fails closed); - remote logout — an admin can revoke a surveyor's sessions/tokens; - immutable audit events for privileged and destructive actions. ## International transfers & sub-processors Primary hosting and the evidence backup are London (europe-west2) . Subprocessors and any international-transfer position are published in the [Subprocessor Register](https://housingsurvey.pro/legal/subprocessors/). Customer-supplied AI keys mean AI processing occurs under the customer's own provider agreement. ## Breach response Evidence-tamper detections follow a documented internal procedure that mandates disclosure over concealment and preserves original bytes. The DPA commits us to notify controllers without undue delay and assist with UK GDPR Arts.33–34, and a general incident-response plan (severity model, response lifecycle, and the processor/controller breach-notification duties including the ICO 72-hour threshold) is now documented. The tabletop exercise needed to evidence repeatable 72-hour support is still outstanding, so that support is partially implemented , not claimed complete. Status: living document. Export, deletion, the DPA and subprocessor register are implemented/published, and an Art. 30 Record of Processing Activities plus a DSAR-handling procedure are now maintained. The per-organisation evidence-retention control and the incident-response tabletop exercise remain open. [← Back to trust & security handbook](https://housingsurvey.pro/legal/technical/) --- ## Compliance Mapping — UK GDPR · SOC 2 · ISO/IEC 27001 · Cyber Source: https://housingsurvey.pro/legal/technical/compliance-mapping/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) / Compliance Mapping — UK GDPR · SOC 2 · ISO/IEC 27001 · Cyber Essentials # Compliance Mapping — UK GDPR · SOC 2 · ISO/IEC 27001 · Cyber Essentials ProSurvey Apps Limited (company no. 17118570) · Trust & Security Handbook Contents - [How to read this](#how-to-read-this) - [Security governance & policies](#security-governance-policies) - [Access control & identity](#access-control-identity) - [Cryptography & data protection](#cryptography-data-protection) - [Integrity & evidential controls](#integrity-evidential-controls) - [Data subject rights & privacy](#data-subject-rights-privacy) - [Operations, resilience & suppliers](#operations-resilience-suppliers) - [Certification and assurance status](#certification-and-assurance-status) Audience: security reviewers, auditors and procurement teams completing a security questionnaire or RFP. Last evidence review: 15 July 2026 . This page maps shipping controls and documented gaps; it does not claim a certification or independent assurance report that HousingSurvey Pro does not hold. ## How to read this - Implemented (✅): built and operating in the production service today. - Partially implemented (🟡): useful control exists, but the stated gap means it is not yet complete across the intended scope. - Planned (⬜): documented intent only; do not rely on it as a control. The status is about HousingSurvey Pro's own control implementation, not certification. Framework references are the [ICO's UK GDPR security guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/security-outcomes/), [ICO breach-reporting guidance](https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/personal-data-breach-management/reporting-processes/), [ISO/IEC 27001:2022](https://www.iso.org/standard/27001) and the [AICPA SOC 2 examination guidance](https://www.aicpa-cima.com/cpe-learning/publication/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy). Control identifiers are a practical cross-reference, not an auditor's opinion. ## Security governance & policies Control Frameworks Status Current evidence and limits Information security policy set (ISMS) ISO A.5.1, SOC 2 CC1.1, CC5.3 ✅ A maintained internal ISMS policy set covers information security, access control, incident response, business continuity/DR, data retention and disposal, vendor management, and internal acceptable use. The founder is the accountable owner acting as interim CISO; each policy states the compensating controls used in a one-person company (append-only hash-chained audit, the nightly integrity verifier, and CI gates as an automated second reviewer). Drafted internally, not independently assured, and not a certification. Access-review cadence ISO A.5.18, SOC 2 CC6.2, CC6.3 🟡 A quarterly access-review procedure with a concrete Firebase/Google Cloud checklist (superadmin claims, IAM, per-org membership, overrides, API/SCIM tokens, SSO) is defined. The first documented review cycle has not yet run. Supplier / sub-processor management ISO A.5.19–A.5.22, SOC 2 CC9.2 ✅ A vendor-management policy governs onboarding criteria and at-least-annual review over the maintained, published [Subprocessor Register](https://housingsurvey.pro/legal/subprocessors/), with 30-day customer notice of changes. Risk and gap tracking ISO A.5.7, SOC 2 CC3.1–CC3.4 ✅ An internal gap register records each open item with a severity, owner and status; founder-only actions are mirrored to the internal action list. Available to procurement/auditors on request. ## Access control & identity Control Frameworks Status Current evidence and limits Role baselines and least privilege ISO A.5.15, SOC 2 CC6.1, UK GDPR Art.32 ✅ Eight organisation roles supply backwards-compatible module baselines through a shared, parity-tested evaluator. Live member role/status and effective levels are enforced in callables, Firestore rules, Storage rules and the apps. See [Access Control & Permissions](https://housingsurvey.pro/legal/technical/access-control/). Per-member module overrides ISO A.5.15, SOC 2 CC6.1 ✅ Authorised module administrators can replace a non-owner member's baseline with sparse None/View/Edit/Module-admin levels. The audited callable is the only writer; changes are document-backed and immediate, malformed state fails closed, and the portal shows baseline, override, effective level and scope. Tenant and record scope enforced server-side SOC 2 CC6.1, ISO A.5.15 ✅ Active organisation membership, default-deny Firestore/Storage rules and emulator denial tests enforce the boundary independently of the UI. Storage image paths resolve their survey/work order and retain assignment checks; legacy paths that cannot prove assignment are closed to new writes. Server-only privileged surfaces SOC 2 CC6.1 ✅ Member/role/permission mutations, audit events, API keys, billing, private provider settings and evidence-sealing fields are client-unwritable and changed through authorised server logic. MFA for privileged users ISO A.5.17, SOC 2 CC6.1 🟡 TOTP/passkey enrolment and manager+ application gates exist; platform-superadmin rules/callables require a current second-factor proof. Equivalent server-side step-up enforcement is not yet universal for ordinary manager/org-admin actions. Remote session revocation SOC 2 CC6.1, UK GDPR Art.32 ✅ Organisation admins can revoke a member's refresh tokens; users can sign out all of their own sessions. Both paths are audited. SSO and automated provisioning ISO A.5.16, SOC 2 CC6.1 ✅ Enterprise admins can configure Entra-compatible OIDC/SAML and mint a hashed SCIM bearer token; SCIM joiner/leaver operations enforce tenant scope and seat rules. See [SSO setup](https://housingsurvey.pro/legal/help/integrations-sso/). Operative least-privilege baseline ISO A.5.15, SOC 2 CC6.1 ✅ The inherited operative baseline is works-only. Record-bearing field modules remain limited to assigned records even when upgraded. An authorised administrator may explicitly grant an administrative/non-record module at organisation scope; the UI labels that as outside the role baseline and the server retains its normal module limits. ## Cryptography & data protection Control Frameworks Status Current evidence and limits Encryption in transit ISO A.8.24, SOC 2 CC6.7, UK GDPR Art.32 ✅ Customer and integration endpoints use managed HTTPS/TLS. Encryption at rest ISO A.8.24, SOC 2 CC6.7, UK GDPR Art.32 ✅ Firestore and Cloud Storage use managed encryption at rest. Password handling UK GDPR Art.32, ISO A.8.24 ✅ Passwords are delegated to Identity Platform and are never stored or logged by application code. Secret and key protection SOC 2 CC6.1, ISO A.8.24 ✅ Platform secrets use managed server-side injection; tenant provider credentials are rules-denied private records; API/SCIM tokens are stored as hashes and displayed once. Production app/client attestation SOC 2 CC6.6 ✅ App Check is enforced on production Firestore, Storage, Identity Toolkit, OAuth, Maps and Places. Web/native clients use reCAPTCHA Enterprise, App Attest or Play Integrity. Nonprod is deliberately monitor-only so it must not be treated as enforcement evidence. Branded authentication email ISO A.5.16, SOC 2 CC6.1 🟡 Branded templates and custom-domain configuration are present. The provider's admin API still reports the custom-domain verification state as incomplete, so custom-domain delivery is not claimed as fully proven. ## Integrity & evidential controls Control Frameworks Status Current evidence and limits Sealed, tamper-evident records ISO A.8.15, SOC 2 CC7.2 ✅ Server-authoritative finalisation, canonical SHA-256 hashes and a per-property chain; client/API rules prevent mutation of sealed content. See [Evidence Integrity](https://housingsurvey.pro/legal/technical/evidence-integrity/). Integrity verification and alerting SOC 2 CC7.2, CC7.3 ✅ The scheduled verifier recomputes chains, records clean runs and raises quarantine metadata, audit events and organisation notifications on mismatches. Change/version history retained ISO A.8.15, UK GDPR Art.5(1)(f) ✅ A correction creates a new sealed version with lineage/version/supersedes fields; prior versions remain retrievable and are included in organisation export. Audit-logged lifecycle transitions ISO A.8.15, SOC 2 CC7.2, CC8.1 ✅ Work-order cancellation, proxy completion, external-summary marking, works attestation and case closure are server-authorised and append immutable, hash-chained audit events with actor/reason. Incident response ISO A.5.24–A.5.26, SOC 2 CC7.4 🟡 A tested evidence-tamper runbook preserves original bytes and prioritises disclosure, and a general incident-response plan (severity model, response lifecycle, and the controller/processor breach duties) is now documented. The general-incident tabletop/exercise has not yet been run. ## Data subject rights & privacy Control Frameworks Status Current evidence and limits Lawful basis and data minimisation UK GDPR Arts.5–6, 25 ✅ The service records property-condition evidence rather than resident profiles; purposes, roles and lawful bases are documented in [Data Protection & GDPR](https://housingsurvey.pro/legal/technical/data-protection/) and the [Privacy Policy](https://housingsurvey.pro/legal/privacy/). Access and portability export UK GDPR Arts.15, 20 ✅ Organisation admins can download a signed ZIP covering all survey versions, work orders, properties, members, audit, billing and a photo manifest; export is audited. Erasure/offboarding with authority and audit UK GDPR Art.17 ✅ Self-service personal-data deletion and cancellable organisation deletion are server-authorised and audited; sealed legal-claims evidence is retained/redacted under the documented exception rather than silently destroyed. Records of processing activities (RoPA) UK GDPR Art.30 ✅ An Art.30 record covering both our processor activities (tenant/property evidence, work orders, customer staff accounts) and our controller activities (account, billing, consent-gated website/product analytics) is maintained internally and provided to controllers/auditors on request. It reflects the real data model, including the optional controller-supplied tenant-contact fields. Maintained internally; not independently assured. Customer Data Processing Agreement UK GDPR Art.28 ✅ The current [DPA](https://housingsurvey.pro/legal/dpa/) is published and covers processor duties, rights assistance, breach notification, deletion/return, subprocessors and technical measures. Legal review/countersignature may still be required for a customer's procurement process. Personal-data breach notification support UK GDPR Arts.33–34 🟡 The DPA commits to notify controllers without undue delay and assist with Arts.33–34, and the incident-response plan documents the processor/controller notification duties and the ICO 72-hour threshold. The exercise needed to evidence repeatable 72-hour support is not yet complete. Retention enforcement and configuration UK GDPR Art.5(1)(e), ISO A.8.10 🟡 Live scheduled janitors enforce configured draft/org deletion windows and a 90-day EDI artefact default while retaining audit/accounting records; the full retention schedule by data class is documented in a Data Retention & Disposal policy. A customer-admin per-organisation evidence-retention control is still planned. ## Operations, resilience & suppliers Control Frameworks Status Current evidence and limits Firestore PITR and scheduled backups ISO A.8.13, SOC 2 A1.2 ✅ Production PITR is enabled with a seven-day version window plus daily backups retained for 98 days. Nonprod has only Firestore's one-hour baseline and no scheduled backup. Firestore recovery testing ISO A.5.30, SOC 2 A1.2 🟡 A nonprod drill recovered changed/deleted documents by point-in-time reads into an isolated database. The production-equivalent PITR bulk export/import and scheduled-backup restore paths have not yet been exercised. Cloud Storage recovery ISO A.8.13, SOC 2 A1.2 ✅ Both evidence buckets have versioning, 14-day soft delete and 30-day noncurrent-version cleanup. Production mirrors nightly to a separate versioned Archive bucket in London; the scheduled 15 July run succeeded. The backup is same-region to preserve UK residency, so it protects bucket/object loss but not a whole-London-region outage. Availability and error monitoring SOC 2 A1.1, CC7.2 🟡 Managed cloud metrics, chain alerts, web performance/error telemetry and native Crashlytics code exist. Native Crashlytics awaits the next store binary, backup-job failure alerting and a published SLO/alert policy remain open. Change management and CI gates SOC 2 CC8.1, ISO A.8.32 ✅ CI runs lint, coverage-gated tests, type/build checks, emulator rules tests and hash-twin parity; production deploys depend on CI and a protected environment. Deployment-environment integrity SOC 2 CC8.1, ISO A.8.32 ✅ Bundle identity assertions and Firebase hosting predeploy hooks block a prod/nonprod asset mix-up even when the raw deploy CLI is used. Subprocessor register and residency disclosure UK GDPR Art.28, ISO A.5.19 ✅ The maintained [Subprocessor Register](https://housingsurvey.pro/legal/subprocessors/) identifies purpose, entity and transfer/residency position. The primary Firestore/Functions/Storage data plane and evidence backup are London-hosted; disclosed ancillary subprocessors may involve international transfers under stated safeguards. Vulnerability management ISO A.8.8, SOC 2 CC7.1 🟡 Automated dependency update workflows and CI checks exist; a formal vulnerability-management policy, remediation SLA and completed independent penetration test remain outstanding. ## Certification and assurance status - UK GDPR: a legal compliance posture, not a certificate. The implemented controls and gaps above are the evidence; customers remain controllers for their own use of the service. - SOC 2: no SOC 2 report has been obtained. A SOC 2 examination is an independent CPA assessment of control design/operation; this mapping is not a substitute. - ISO/IEC 27001:2022: not certified. Control alignment does not equal an accredited certificate or a complete ISMS. - Cyber Essentials: not certified. Technical alignment and roadmap work do not constitute an IASME assessment or certificate. We will use “certified”, “attested” or “SOC 2 report” only when the relevant independent evidence exists and will make it available through the appropriate procurement channel. Status: living control register. Evidence and gaps were checked against the shipping repository and live production/non-production configuration on 15 July 2026. A ✅ records a current control, not a promise that every adjacent governance process is complete. [← Back to trust & security handbook](https://housingsurvey.pro/legal/technical/) --- ## Access Control & Permissions Model | HousingSurvey Pro Source: https://housingsurvey.pro/legal/technical/access-control/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) / Access Control & Permissions Model # Access Control & Permissions Model ProSurvey Apps Limited (company no. 17118570) · Trust & Security Handbook Contents - [Identity](#identity) - [Authorisation model](#authorisation-model) - [Role baselines](#role-baselines) - [Granular permissions (implemented)](#granular-permissions-implemented) - [Server-only surfaces](#server-only-surfaces) - [Session & credential lifecycle](#session-credential-lifecycle) - [Auditing](#auditing) Audience: security reviewers, IT admins, procurement. Describes how identity, roles and permissions work in HousingSurvey Pro. This page also serves as the operating reference for the granular permissions model. Remaining gaps are marked planned / in progress . ## Identity Users authenticate through Firebase Auth / Identity Platform. Three sign-in paths, one identity model underneath: - Email + password — office staff, managers, contractors with email. - SSO (Microsoft Entra ID) — self-service OIDC or SAML federation, with SCIM 2.0 joiner/leaver provisioning for Enterprise organisations. - Tenant username/code + passcode — field surveyors and third parties without email. These are provisioned by a tenant admin in the management dashboard ; each maps to a Firebase identity under an internal alias so the same rules, claims and audit apply. Passwords are held by the identity platform, never by the application. Multiple profiles / multi-tenancy: one person may hold accounts in several tenants (e.g. a surveyor working for two housing associations). The mobile app stores multiple tenant-scoped profiles and lets the user switch between them; email accounts can span tenants as multiple memberships. Each session is scoped to exactly one tenant at a time. ## Authorisation model Custom token claims identify the organisation context presented by a signed-in user, but they are not the sole authority for a privileged action. Firestore and Storage rules require an active membership whose current role still matches the claim. Callable functions load the active member document and current role for each request, so archiving a member or changing their role is not deferred until an old token expires. The same checks load the member's server-written memberPermissions/{uid} document. The UI mirrors the resulting access for usable feedback; Firestore rules, Storage rules and callable checks are the enforcement boundaries and deny independently of the UI. ### Role baselines Each organisation role supplies a backwards-compatible default for every permission module. A sparse per-member override may raise or lower that default; removing an override restores the role baseline. The shared evaluator has a parity-tested server copy, and the rules and callable checks evaluate the same levels from live documents. Role Scope System admin (superadmin) Platform operations; current TOTP/passkey proof required; cannot be created by an organisation role or module grant and cannot alter sealed evidence Owner Everything an org admin can, plus the two irreversible actions: ownership transfer and organisation deletion Org admin Full control within one organisation (settings, members, billing) except ownership transfer and org deletion Manager Day-to-day operations: work orders, scheduling, properties, evidence read/export, case notes, member list Coordinator Office staff: raises work orders, schedules visits, keeps case notes; reads evidence and dashboards — no exports, deletions, settings or member changes Finance Billing and invoices only, plus dashboards Viewer Read-only evidence and dashboards Surveyor Field-capture baseline. Evidence, properties, work orders and scheduling remain assignment-scoped even when explicitly upgraded Operative Works-only baseline for assigned remediation and photo capture. Record-bearing modules remain assignment-scoped. Free seat class; may be contractor, subcontractor or landlord staff Contractor is an organisation relationship, not an extra member role. A contractor organisation reaches a landlord's records only through its active grant and the relevant work-order/record scope. ### Granular permissions (implemented) An authorised administrator can tune a non-owner member from None through Module admin for each product area. Module admin is not platform system admin and cannot create owner-only or superadmin authority: - Modules — each dashboard area and app capability is a permissionable unit (Evidence, Properties, Work orders, SOR/rates, Scheduling, Settings, Billing, Reports, etc.). - Levels per module — e.g. none → view → edit → admin . - Assignment — a member gets a role baseline plus optional sparse, per-module overrides. Inherit role removes the stored override. - Scope — surveyor/operative evidence, properties, work orders and scheduling remain limited to assigned records. An explicit grant to an administrative or other non-record module can be organisation-scoped. - Enforcement — the portal and capture app load the effective level only after the live permission document resolves. Firestore rules, Storage rules and callable functions evaluate the live role, override and required scope. - Immediate effect — changes do not wait for a custom-claim refresh. Missing documents inherit the role baseline; malformed documents or read failures fail closed. - Governance — owner permissions are fixed; members cannot change their own permissions; the caller cannot grant above their own effective level; every successful replacement is audit-logged. Storage evidence paths include their survey or work-order id. Rules resolve the linked record before allowing a read or append-only image create, retain the assignment check for field identities, deny direct bundle access, and deny new writes to legacy property-keyed paths that cannot prove assignment. ## Server-only surfaces Some data is never client-writable, even by an org admin — writes happen only through audited server logic: - organisation members / roles / permission overrides , audit events , API keys , billing ; - organisation private secrets (webhook secrets, provider config); - evidence finalisation fields (hashes, chain sequence) — set server-side at sealing, never by a client. ## Session & credential lifecycle - Provisioning: tenant admins mint field logins and invite email users. - Suspension / offboarding: accounts can be suspended or removed with audit. - Remote logout: an admin can revoke a member's refresh tokens; users can revoke all their own sessions. Both server paths are audited. - MFA: TOTP and passkeys are available. Manager+, org-admin and owner roles are gated in the apps, and platform-superadmin rules/callables require a current TOTP/passkey proof. Universal server-side step-up enforcement for ordinary manager/org-admin operations remains in progress. ## Auditing Privileged and destructive actions (member/role changes, deletions, billing, integrity events) are written as immutable audit events , queryable by org admins and retained as evidence. Status: the identity model, role baselines, live per-member module overrides, assignment-aware Firestore/Storage/callable enforcement, remote revocation, SSO and SCIM are implemented and deployed in production and nonproduction. Ordinary manager/org-admin server-side MFA step-up remains the scoped gap described above. [← Back to trust & security handbook](https://housingsurvey.pro/legal/technical/) --- ## Sub-processors & Data Residency | HousingSurvey Pro Source: https://housingsurvey.pro/legal/subprocessors/ [Legal & compliance](https://housingsurvey.pro/legal/) / Sub-processors & Data Residency # Sub-processors & Data Residency Version 1.0 · Effective date: 14 July 2026 · ProSurvey Apps Limited (company no. 17118570), registered in England and Wales. This document is product-accurate and drafted to be thorough, but it is not legal advice . Questions: [contact us](https://housingsurvey.pro/contact/) or email support@prosurvey.app. See also: [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) · [Privacy Policy](https://housingsurvey.pro/legal/privacy/) · [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) Contents - [Data residency](#data-residency) - [Core sub-processors](#core-sub-processors) - [Marketing-website analytics and advertising (consent-based)](#marketing-website-analytics-and-advertising-consent-based) - [Customer-keyed AI providers (the Controller's own choice, not ours)](#customer-keyed-ai-providers-the-controllers-own-choice-not-ours) - [External data sources — no personal data sent](#external-data-sources-no-personal-data-sent) - [Changes and notification](#changes-and-notification) This register lists the third parties who process data on our behalf, where that data is held, and — for anything that leaves the UK — the transfer safeguard relied on. ## Data residency All platform data (Firestore database, Cloud Storage, Cloud Functions, and authentication) is stored and processed in the Google Cloud London region (europe-west2) , enforced in our codebase. Static assets (website, portal, app bundles) are code, not customer data, and are distributed via CDN. ## Core sub-processors Sub-processor Role Location / residency Google Cloud / Firebase Core hosting, database, storage, authentication, serverless functions, app attestation UK (europe-west2, London) for the data plane Stripe Card payments and invoicing UK/EU and US-headquartered; card data is out of our scope entirely (Stripe is PCI-DSS certified). Any transfer outside the UK is under Stripe's standard contractual clauses (or equivalent transfer mechanism) Cloudflare CDN, DNS, WAF, Turnstile bot protection Global CDN network, US-headquartered; any transfer outside the UK is under Cloudflare's standard contractual clauses (or equivalent transfer mechanism) Google Workspace (SMTP) Transactional / notification email US-headquartered (Google LLC) / Ireland (Google Ireland Ltd); any transfer outside the UK is under Google's standard contractual clauses (or equivalent transfer mechanism) Ordnance Survey / Google Places Address-to-UPRN resolution and address autocomplete (address strings only — no tenant personal data) Ordnance Survey: UK. Google Places: US-headquartered; any transfer outside the UK is under Google's standard contractual clauses (or equivalent transfer mechanism) EPC register (gov.uk) Energy-performance lookups for a property (address/property identifiers only) UK — a public register Google (AI Studio) — public docs assistant only Powers the public documentation assistant on our website; no Customer or Tenant Personal Data US-headquartered; touches only public marketing/documentation content ## Marketing-website analytics and advertising (consent-based) Set only if you accept our cookie-consent banner — see the Cookie Notice . Provider Purpose Location Meta (Meta Pixel) Advertising and campaign measurement Meta Platforms Ireland Ltd / Meta Platforms, Inc. (US-headquartered); transfer under Meta's standard contractual clauses LinkedIn (Insight Tag) Advertising and campaign measurement LinkedIn Ireland Unlimited Company / LinkedIn Corporation (US-headquartered); transfer under LinkedIn's standard contractual clauses Google (Firebase Analytics / Google Analytics 4) Website usage analytics; also the portal/app's automatic product analytics (no cookie banner in signed-in products) Google Ireland Limited / Google LLC (US-headquartered); transfer under Google's standard contractual clauses Google (Firebase Performance Monitoring) Website and portal loading-speed / technical-performance measurement Google Ireland Limited / Google LLC (US-headquartered); transfer under Google's standard contractual clauses Google (Firebase Crashlytics) Native crash reporting in the mobile apps only Google Ireland Limited / Google LLC (US-headquartered); transfer under Google's standard contractual clauses ## Customer-keyed AI providers (the Controller's own choice, not ours) If a customer enables advisory AI assistance on survey content, that processing runs on the customer's own AI provider account and API key — for example Anthropic, Azure OpenAI, OpenAI, Google, or a compatible endpoint the customer configures. That processing is governed by the customer's own agreement with the provider it chooses, not by any agreement of ours. We store the key server-side only, scope its use strictly to that customer, refuse AI actions on finalized records, and fail closed when no key is configured. This row is listed here for transparency only. Provider type Purpose Engaged when AI provider (Anthropic / Azure OpenAI / OpenAI / Google / BYO endpoint) Advisory survey-content drafting and photo analysis — advisory only, never enters the sealed evidence record automatically The customer adds their own key in Settings → AI Identity provider (Microsoft Entra ID) Single sign-on for the customer's own staff The customer connects SSO on an eligible plan ## External data sources — no personal data sent Some features call public data services keyed on location, not identity ; no resident personal data is transmitted: - Weather normals / current conditions (by coordinates or postcode). - Soil data (by coordinates). - Map tiles (by coordinates). - UK EPC register lookup (by address/postcode, via a server-side key). ## Changes and notification We will give at least 30 days' prior notice of any intended addition or replacement of a sub-processor, by updating this page and, where you have subscribed, notifying your organisation administrators, giving you a reasonable opportunity to object on reasonable data-protection grounds (see the DPA, clause 5.3). ProSurvey Apps Limited · registered in England and Wales, company number 17118570 · HousingSurvey Pro™. ## Changelog - v2.4 (14 July 2026) — Full UK-law B2B SaaS suite drafted (W-E1), published live (W-E2/H-LEGAL-PUBLISH). Supersedes the v1.0 short-form page. --- ## Privacy Policy | HousingSurvey Pro Source: https://housingsurvey.pro/legal/privacy/ [Legal & compliance](https://housingsurvey.pro/legal/) / Privacy Policy # Privacy Policy Version 2.4 · Effective date: 14 July 2026 · ProSurvey Apps Limited (company no. 17118570), registered in England and Wales. This document is product-accurate and drafted to be thorough, but it is not legal advice . Questions: [contact us](https://housingsurvey.pro/contact/) or email support@prosurvey.app. See also: [Terms of Service](https://housingsurvey.pro/legal/terms/) · [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) · [Acceptable Use Policy](https://housingsurvey.pro/legal/aup/) · [Cookie Notice](https://housingsurvey.pro/legal/cookies/) · [Sub-processors](https://housingsurvey.pro/legal/subprocessors/) Contents - [1. Who we are](#1-who-we-are) - [2. Our two roles — controller and processor](#2-our-two-roles-controller-and-processor) - [3. What we process, why, and our lawful basis](#3-what-we-process-why-and-our-lawful-basis) - [3.1 As controller (account, billing, website)](#31-as-controller-account-billing-website) - [3.2 As processor (evidence / Tenant Personal Data)](#32-as-processor-evidence-tenant-personal-data) - [4. Photographs and location — special care](#4-photographs-and-location-special-care) - [5. Where your data lives — UK residency](#5-where-your-data-lives-uk-residency) - [6. Subprocessors](#6-subprocessors) - [6.1 Customer-keyed AI providers](#61-customer-keyed-ai-providers) - [7. Retention](#7-retention) - [8. Security](#8-security) - [9. Your rights](#9-your-rights) - [10. Cookies and similar technologies](#10-cookies-and-similar-technologies) - [11. Children](#11-children) - [12. Changes](#12-changes) ## 1. Who we are HousingSurvey Pro™ is operated by ProSurvey Apps Limited ("we", "us", "our"), a company registered in England and Wales, company number 17118570 . For any privacy question, or to exercise your rights, use our [contact form](https://housingsurvey.pro/contact/) or email our support address (published on our website). Our company registration record, including our registered office, is publicly searchable on the UK Companies House register under company number 17118570 . We respond within one calendar month. We have not designated a separate named Data Protection Officer: UK GDPR does not require one for a business of our size and processing profile. Privacy enquiries and data-subject requests should be directed to the contact channels above, which we treat as our data-protection contact point. ## 2. Our two roles — controller and processor We act in two distinct capacities , and it matters which one applies to a given piece of data: - Processor — for Tenant/property evidence data captured by our customers (housing associations, councils, and their contractors) and their Authorised Users. Here the customer organisation is the data controller and we are its processor , acting on its documented instructions under our [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) . If you are a resident, occupier or other individual whose data appears in a survey, the housing organisation is your controller — please direct requests to them first (see clause 9). - Controller — for account, billing, support and website data — the data we need to run our business, provide the Service to our customers, and operate our website. ## 3. What we process, why, and our lawful basis ### 3.1 As controller (account, billing, website) Data Purpose Lawful basis (UK GDPR Art. 6) Account data — name, work email, organisation, role Authentication, access control, providing the Service, support Contract (Art. 6(1)(b)) Authentication data — password hashes, passkey (WebAuthn) public keys, TOTP secrets, App Check tokens Securing accounts; two-factor authentication Legitimate interests (security) (Art. 6(1)(f)) Billing data — customer and subscription identifiers, invoice/PO details, payment terms Subscription and invoice management. Card details are handled by Stripe and never touch our systems. Contract; legal obligation (accounting) Support correspondence and contact-form submissions Responding to you; sales/procurement enquiries; spam review and audit Legitimate interests Website security (minimal) Bot protection (Cloudflare Turnstile), security, service integrity Legitimate interests Marketing/advertising cookies — Meta Pixel (Meta) and LinkedIn Insight Tag (LinkedIn) Advertising and campaign measurement — understand which marketing brought a visitor to our site. Set only if you accept our cookie-consent banner — see clause 10 and [Cookie Notice](https://housingsurvey.pro/legal/cookies/) Consent (Art. 6(1)(a)) Website analytics — Firebase Analytics / Google Analytics 4 (Google) Understand website usage and improve the website; also carries a structured technical-error signal (no personal data — see clause 10). Set only if you accept our cookie-consent banner , and only once enabled — see clause 10 and [Cookie Notice](https://housingsurvey.pro/legal/cookies/) Consent (Art. 6(1)(a)) Website performance monitoring — Firebase Performance Monitoring (Google) Measure website loading speed and technical performance. Set only if you accept our cookie-consent banner , and only once enabled — see clause 10 and [Cookie Notice](https://housingsurvey.pro/legal/cookies/) Consent (Art. 6(1)(a)) Portal/app usage analytics — Firebase Analytics / Google Analytics 4 (Google) Understand product usage and improve the portal/apps; also carries a structured technical-error signal. Collected automatically (anonymised page/screen views and key actions only; never your Evidence or organisation data) — see clause 10 Legitimate interests (Art. 6(1)(f)) Mobile app crash reporting — Firebase Crashlytics (Google) Native crash reports (stack trace, device/OS info, app version) to diagnose and fix app crashes. Not linked to your account identity. Collected automatically , no opt-in toggle — see clause 10 Legitimate interests (Art. 6(1)(f)) Audit data (who did what, when, in the Service) Evidence integrity, security, fraud prevention Contract / legitimate interests ### 3.2 As processor (evidence / Tenant Personal Data) We process the following on our customers' behalf, on their instructions, under the DPA. The customer is the controller and determines the lawful basis (typically a legal obligation or legitimate interests relating to housing standards): Data Notes Property data — addresses, UPRNs, EPC data Address strings sent to address/EPC lookups (see subprocessors) Environmental readings and observations Temperature, humidity, condition notes, HHSRS/IAQ inputs Photographs of homes Special care — see clause 4 Inspection GPS fix Special care — see clause 4 Surveyor and Authorised-User identifiers Who captured/edited a record; sealed with it Work orders, deadlines, statutory-stage timestamps Awaab's Law tracking data Records are designed to describe properties, not people. Customers are contractually required (see the Terms and DPA) not to enter tenant personal data, and never special-category data, into free-text or evidence fields, and to minimise any personal data they do enter. ## 4. Photographs and location — special care Photographs of homes and a precise GPS fix can be sensitive. Accordingly: - Photographs are captured to evidence property condition and are content- hashed and sealed with the Evidence Record. They should show building fabric/conditions, not identifiable individuals; customers instruct their surveyors accordingly. - Location is captured only when a surveyor deliberately captures a GPS fix during an inspection, to geo-stamp the record at the point of capture. There is no background tracking, no movement history, and no advertising use. As processor, we hold this data for the controlling organisation; requests about it should go to that organisation (clause 9). ## 5. Where your data lives — UK residency All platform data (Firestore database, Cloud Storage, Cloud Functions, and authentication) is stored and processed in the Google Cloud London region (europe-west2) . Region pinning is enforced in our codebase. Website and portal static assets are code, not customer data, and are served via CDN. International transfers are limited to what our subprocessors necessarily involve (clause 6); where any transfer outside the UK occurs, it is made under an appropriate safeguard (for example, the UK IDTA/Addendum to the EU Standard Contractual Clauses, or an adequacy decision), as set out per subprocessor on the [subprocessors page](https://housingsurvey.pro/legal/subprocessors/). Marketing/advertising cookies, analytics and diagnostics specifically (clause 10, [Cookie Notice](https://housingsurvey.pro/legal/cookies/)): Meta Pixel (Meta Platforms Ireland Ltd / Meta Platforms, Inc., both US-headquartered), LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company / LinkedIn Corporation, US-headquartered), Firebase Analytics / Google Analytics 4 , Firebase Performance Monitoring and Firebase Crashlytics (each Google Ireland Limited / Google LLC, US-headquartered) each involve a transfer of the relevant data outside the UK when set. The website trackers (Meta Pixel, LinkedIn Insight Tag, Firebase Analytics, Firebase Performance Monitoring) load only if you accept our cookie-consent banner . The portal/app analytics and technical-error reporting, and the mobile apps' Crashlytics crash reporting, are automatic in our signed-in products (legitimate interests — see clauses 3.1 and 10; anonymised usage/diagnostic data only, never your Evidence or organisation data). Each provider relies on its own standard contractual clauses (or equivalent transfer mechanism) as data importer. ## 6. Subprocessors We use the following subprocessors. AI providers used for survey-content assistance are the customer's own — see clause 6.1. Subprocessor Purpose Data / notes Google Cloud / Firebase Hosting, database (Firestore), storage, authentication, Cloud Functions Core data plane — pinned to europe-west2 (London) Stripe Card payments and invoicing Payment card data handled by Stripe (PCI-DSS); we store only customer/subscription identifiers Cloudflare CDN, DNS, WAF, and Turnstile bot-protection on website forms Turnstile processes a challenge token/IP for bot detection; minimal, security purpose Google Workspace (SMTP relay) Sending transactional and notification email (e.g. from a no-reply platform address) Email metadata and content of platform emails Ordnance Survey / Google Places Address-to-UPRN resolution and address autocomplete Address strings only — no tenant personal data EPC register (gov.uk) Energy-performance lookups for a property Address/property identifiers only; a public register Google (AI Studio) — public docs assistant only Powers the public documentation assistant on our website Only public marketing/documentation content — never Customer Data, Tenant Personal Data, or an auth token Meta (Meta Pixel) Advertising and campaign measurement on the marketing website Consent-based — set only if you accept our cookie-consent banner; see clause 10 and [Cookie Notice](https://housingsurvey.pro/legal/cookies/) LinkedIn (Insight Tag) Advertising and campaign measurement on the marketing website Consent-based — set only if you accept our cookie-consent banner; see clause 10 and [Cookie Notice](https://housingsurvey.pro/legal/cookies/) Google (Firebase Analytics / Google Analytics 4) Website usage analytics (marketing website) and product usage analytics (portal/apps); also carries a structured technical-error signal on each surface Website: consent-based — set only if you accept our cookie-consent banner. Portal/apps: automatic (legitimate interests, no cookie banner or toggle in a signed-in app); see clause 10 and [Cookie Notice](https://housingsurvey.pro/legal/cookies/) Google (Firebase Performance Monitoring) Website loading-speed and technical-performance measurement (marketing website and portal) Website: consent-based — set only if you accept our cookie-consent banner. Portal: automatic (legitimate interests); timings and request URLs only, no page content; see clause 10 and [Cookie Notice](https://housingsurvey.pro/legal/cookies/) Google (Firebase Crashlytics) Native crash reporting in the mobile apps Automatic (legitimate interests) — stack trace, device/OS info, app version; not linked to your account identity; see clause 10 and [Cookie Notice](https://housingsurvey.pro/legal/cookies/) ### 6.1 Customer-keyed AI providers If a customer enables advisory AI assistance on survey content, that processing runs on the customer's own AI provider account and API key (for example, Anthropic, Azure OpenAI, OpenAI, Google, or a compatible endpoint the customer configures). The customer's relationship with that AI provider — including the data-processing agreement — is the customer's own. We store the customer's key server-side only, scope its use strictly to that customer, refuse AI actions on finalized records, and fail closed when no key is configured. AI output is advisory and never enters the sealed evidential record automatically. We give notice of material subprocessor changes as set out in the [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) . The current, up-to-date list is also published on the [subprocessors page](https://housingsurvey.pro/legal/subprocessors/). ## 7. Retention - Finalized Evidence Records are intentionally tamper-evident : no client or API path can edit or delete them, and any change to a sealed record by any means breaks its cryptographic hash chain and is detected automatically. They are retained for the period the controlling organisation sets (default reflects housing-disrepair limitation periods, commonly six years or longer). We do not claim a finalized record can never be altered at the infrastructure layer; we claim any such change cannot be made undetectably (see the [Terms of Service](https://housingsurvey.pro/legal/terms/), clause 2.4). - Draft records can be soft-deleted with an audit trail. Soft-deleted drafts leave an audit tombstone ; their heavy payload and photos are purged by an automated janitor after a retention window (default around 30 days), while the tombstone/audit record is kept. - Deleted organisations are purged by an automated sweep after their deletion window (self-service organisation deletion: a 90-day cancellable window; superadmin-initiated deletion: a shorter documented cool-down), subject to records we must legally keep. - Audit logs are retained with the evidence they protect. - Account personal data is deleted within 90 days of account closure. - Accounting/billing records are retained for six years to meet UK accounting-retention requirements, after which they are removed. - EDI/export artefacts are retained on a rolling window (default around 90 days). Where UK GDPR erasure rights are engaged for personal data inside Evidence Records, we work with the controller, noting the Article 17(3)(e) exemption (retention for the establishment, exercise or defence of legal claims). ## 8. Security TLS in transit and encryption at rest throughout; default-deny access rules with per-organisation isolation; server-authoritative finalization with cryptographic hash chains and append-only audit logs; app attestation (App Check); two-factor authentication (TOTP or passkey); credentials and API keys stored only as salted hashes. We describe our full posture, honestly, on our website's security page. We do not currently hold SOC 2, ISO/IEC 27001 or Cyber Essentials certification ; we operate to those control frameworks and are working towards certification. We make no certification claim unless and until certified. ## 9. Your rights Under UK GDPR and the Data Protection Act 2018 you may request access, rectification, erasure, restriction, portability, or object to processing. - For evidence/tenant data (where we are processor): contact the housing organisation that holds the record — it is your controller. We support that organisation with real, self-service tools: an org-administrator can export all of an organisation's data (as a signed ZIP) and can request full organisation deletion, both without needing a support ticket. - For account, billing and website data (where we are controller): contact us using the details in clause 1. Any user can delete their own account self-service; their personal data on membership records is redacted, while Evidence Records survive under an opaque identifier (Art. 17(3)(e)). You have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk . We would appreciate the chance to resolve your concern first. ## 10. Cookies and similar technologies We set no advertising or analytics cookies without your consent . Our website uses a cookie-consent banner: strictly-necessary storage — for example authentication/session storage in the portal and app, App Check attestation tokens, and Cloudflare Turnstile for bot protection on forms — is always on, but marketing/advertising and analytics cookies load only if you accept , and you can withdraw that consent at any time via "Manage cookies" in the website footer. The website is configured to set four technologies on consent: Meta Pixel , LinkedIn Insight Tag (advertising and campaign measurement), Firebase Analytics / Google Analytics 4 (website usage analytics plus a structured technical-error signal — unhandled page/script errors, no personal data — when enabled) and Firebase Performance Monitoring (website loading-speed and technical-performance measurement, when enabled) — see clause 6 and the international transfer note in clause 5. Separately, our portal and mobile apps (signed-in products, where there is no cookie banner) use Firebase Analytics / Google Analytics 4 automatically , to understand product usage — anonymised page/screen views and key actions only, plus the same structured technical-error signal; the portal also uses Firebase Performance Monitoring automatically. There is no opt-in toggle; none of it ever collects your Evidence or organisation data. Our mobile apps additionally use Firebase Crashlytics automatically for native crash reporting — stack trace, device/OS information and app version when the app crashes, not linked to your account identity (we make no setUserId call). Crashlytics exists only in the mobile apps; it has no web equivalent, which is why the website and portal use the performance-monitoring and error-signal tools above instead. We rely on legitimate interests (Art. 6(1)(f)) as the lawful basis for this automatic analytics, error, performance and crash reporting in the signed-in products. If you would prefer we not process this diagnostic/analytics data about your organisation's use of the portal or app, contact support and we will consider a technical opt-out. The [Cookie Notice](https://housingsurvey.pro/legal/cookies/) is the authoritative, up-to-date detail for this clause and will be updated first if any of this changes. ## 11. Children The Service is a B2B tool for housing professionals and is not directed at children. We do not knowingly collect personal data about children through our own controller-side processing. ## 12. Changes We post changes here with a new version number and effective date. Material changes affecting organisations are notified to organisation administrators. ProSurvey Apps Limited · registered in England and Wales, company number 17118570 · HousingSurvey Pro™. ## Changelog - v2.4 (14 July 2026) — Full UK-law B2B SaaS suite drafted (W-E1), published live (W-E2/H-LEGAL-PUBLISH). Supersedes the v1.0 short-form page. --- ## Product Help & Guides | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/ [Legal & compliance](https://housingsurvey.pro/legal/) / Help centre # Help centre Step-by-step guides for using HousingSurvey Pro — from your first survey to configuring integrations. Written in tiers: Basics for a first-time user, Deep dive for configuration detail, Technical for API/IT notes. ## Get started - [Getting Started](https://housingsurvey.pro/legal/help/getting-started/) - [The Live Demo — a 20-Minute End-to-End Tour](https://housingsurvey.pro/legal/help/demo-walkthrough/) ## Management dashboard - [Management Dashboard — Evidence](https://housingsurvey.pro/legal/help/dashboard-evidence/) - [Management Dashboard — Properties & Imports](https://housingsurvey.pro/legal/help/dashboard-properties/) - [Management Dashboard — Work Orders & Awaab Timeline](https://housingsurvey.pro/legal/help/dashboard-workorders/) - [Management Dashboard — The Lifecycle, End to End](https://housingsurvey.pro/legal/help/dashboard-lifecycle/) - [Management Dashboard — Repair Rates (Schedule of Rates)](https://housingsurvey.pro/legal/help/dashboard-sor/) - [Management Dashboard — Scheduling & Dispatch](https://housingsurvey.pro/legal/help/dashboard-scheduling/) - [Management Dashboard — Settings & Permissions](https://housingsurvey.pro/legal/help/dashboard-settings/) - [Management Dashboard — Billing & Invoices](https://housingsurvey.pro/legal/help/dashboard-billing/) - [Management Dashboard — Contractors & Onboarding](https://housingsurvey.pro/legal/help/dashboard-contractors/) ## Integrations - [Integrations — Single Sign-On (Microsoft Entra ID)](https://housingsurvey.pro/legal/help/integrations-sso/) - [Integrations — AI Provider Keys](https://housingsurvey.pro/legal/help/integrations-ai/) - [Integrations — Webhooks & API](https://housingsurvey.pro/legal/help/integrations-api/) - [Integrations — SFTP](https://housingsurvey.pro/legal/help/integrations-sftp/) - [Integrations — Testing Your Connection](https://housingsurvey.pro/legal/help/integrations-testing/) ## Mobile capture app - [Mobile App — Install & Sign In](https://housingsurvey.pro/legal/help/app-signin/) - [Mobile App — Running a Survey](https://housingsurvey.pro/legal/help/app-survey/) - [Mobile App — Offline & Sync](https://housingsurvey.pro/legal/help/app-offline/) Looking for security, data-protection or compliance detail instead? See the [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/). --- ## Integrations — Testing Your Connection | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/integrations-testing/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Integrations — Testing Your Connection # Integrations — Testing Your Connection ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [Basics — what to test, and where](#basics-what-to-test-and-where) - [Deep dive — one integration at a time](#deep-dive-one-integration-at-a-time) - [Webhook](#webhook) - [REST API](#rest-api) - [HACT payload shape](#hact-payload-shape) - [EDI flat-file (CSV)](#edi-flat-file-csv) - [SFTP server](#sftp-server) - [SMTP (statutory deadline emails)](#smtp-statutory-deadline-emails) - [AI provider key](#ai-provider-key) - [Technical — verifying signatures & debugging failures](#technical-verifying-signatures-debugging-failures) - [Verifying a webhook signature](#verifying-a-webhook-signature) - [Common failure causes](#common-failure-causes) - [Residency & auditing](#residency-auditing) Every integration in Settings → API & webhooks has a self-serve way to prove it actually works before you rely on it — no waiting for a real survey to finalize, no guessing whether your endpoint or credentials are right. Written for the person on your side who'll actually wire this up: a housing association IT contact, or your CMS vendor's integration developer. Tiered — Basics for what to click, Deep dive for what "success" looks like, Technical for verifying signatures and debugging failures. ## Basics — what to test, and where Integration Where Test affordance Webhook Settings → API & webhooks → Webhook (push to your CMS) Send test event button REST API Settings → API & webhooks → REST API Quick start curl examples + sample payload viewer HACT payload shape Settings → API & webhooks → REST API View sample HACT payload EDI flat-file (CSV) Settings → API & webhooks → EDI flat-file (CSV) Manual date-range Export CSV run SFTP server Settings → SFTP servers Test connection button SMTP (statutory email) Settings → Notifications (or wherever your SMTP config lives) Test connection button AI provider key Settings → AI Test connection button All of these are org-admin actions, live server-side, and never touch or modify real evidence. ## Deep dive — one integration at a time ### Webhook - Save a webhook URL first (HTTPS only). - Click Send test event . This fires a real, signed test.ping event at your saved URL right now — no queue, no waiting for the next survey to finalize. - Read the result inline: - Green, "Delivered · HTTP 2xx · Nms" — your endpoint accepted the POST. You're done. - Red, with an error or non-2xx status — see [Common failure causes](#common-failure-causes) below. - Expand View sample payload & signature headers sent to see the exact JSON body and x-hsp-signature / x-hsp-event headers your endpoint just received — hand this straight to your dev team so they can build signature verification against real bytes, not guesswork. The test event is signed with your real signing secret, using the same HMAC code path every production survey.finalized delivery uses — so a passing test is a genuine, not simulated, proof that delivery and signature verification both work end-to-end. The payload is clearly marked "sample": true and carries no real evidence — your endpoint should accept it exactly as it would accept a production event, then discard it (or route it to a test log) based on that flag. ### REST API - Mint an API key with the scopes you need (Settings → API & webhooks → REST API ). - Expand Quick start for your organisation's base URL and ready-to-run curl examples for GET /v1/surveys and GET /v1/work-orders — copy one, swap in your real key, and run it from a terminal. - A 200 with a JSON body (even an empty surveys: [] array on a brand-new org) confirms auth, scopes and network access all work. - Expand View sample HACT payload to see the exact shape a real, finalized survey returns — every field populated at once with synthetic data — so you can build a parser before real evidence exists. ### HACT payload shape The sample payload viewer (inside the REST API card) renders the platform's toHact() mapping applied to a synthetic survey, property and work order. It's generated entirely client-side in your browser — nothing is sent to or read from any server for this view. Use it to confirm your CMS's ingest mapping (measurements, hazards, evidence, the Awaab's Law statutory block) matches what you expect before the first real payload arrives. ### EDI flat-file (CSV) The nightly export (02:00 UK) is the production path, but you don't have to wait for it: - Pick a short date range (a day or two of test data, or even a range with zero records — that's a valid test too). - Click Export CSV . This runs the exact same export code the nightly schedule uses, synchronously, and opens the resulting file. - Confirm the column layout matches what your ingest expects, and that the download link works — it expires after 7 days, same as the nightly drop. ### SFTP server - Add a server (Settings → SFTP servers) and, if using a key, mint one and install the public half on your server. - Click Test connection . This runs a real 4-step handshake — connect, negotiate the host key, authenticate, then a read-only check of the remote path — and never writes a file. - Each step shows pass/fail inline. On the first successful test, your server's host-key fingerprint is shown for you to confirm and pin; from then on, a changed fingerprint fails the test closed rather than connecting anyway. ### SMTP (statutory deadline emails) - Save your organisation's SMTP host, port, credentials and from-address. - Click Test connection (Settings → Notifications). This sends a real test email to your own signed-in account's email address using the saved config — the fastest way to prove host/port/auth/TLS all work without touching a live tenant notification. - Check your inbox (and spam folder) for "HousingSurvey Pro — SMTP test email". Arrival confirms the full chain: connection, auth, and delivery. ### AI provider key - Pick a provider and paste your own API key (Settings → AI). - Click Test connection . The platform asks your provider to reply with a single fixed word using your key and resolved model, and reports the result — Connected · provider · model on success, or the provider's own error message (shortened) on failure. - A pass here means AI-assisted features (photo analysis, polish, summaries) will work; a fail means to double-check the key and any provider-side billing/quota setup before relying on them. ## Technical — verifying signatures & debugging failures ### Verifying a webhook signature Every webhook delivery — test or production — carries: - x-hsp-signature : the hex-encoded HMAC-SHA256 of the raw request body , keyed with your organisation's signing secret (shown once when you first saved the webhook URL; regenerate by re-saving if you've lost it). - x-hsp-event : the event name ( test.ping for test events, survey.finalized and deadline events in production). Verify it server-side (pseudocode, any language): expected = hex(hmac_sha256(secret, raw_request_body)) if !constant_time_equals(expected, headers['x-hsp-signature']): reject as 401/403 — do not process Compute the HMAC over the raw bytes of the body exactly as received — re-serializing parsed JSON before hashing will produce a different signature and a false rejection. ### Common failure causes Symptom Likely cause Webhook test times out (no response in 10s) Your endpoint is slow, unreachable, or behind a firewall/VPN that isn't reachable from the public internet — HousingSurvey Pro calls out from europe-west2 (London); check your IP allowlist includes Google Cloud egress ranges for that region, or allow the request generally if you can't pin an IP range. Webhook test returns a non-2xx status Your endpoint rejected the request — check its own logs; a 401/403 usually means signature verification failed (see above); a 404 usually means the URL path is wrong. Webhook signature doesn't match You're hashing the parsed/re-serialized body instead of the raw bytes; or you copied the wrong secret (each save of the webhook URL can rotate the secret — check you have the latest one). REST API returns 401 The Authorization: Bearer header is missing, malformed, or the key was revoked. REST API returns 403 "missing scope" The key wasn't minted with the scope the endpoint needs — mint a new key with the right scopes (existing keys' scopes can't be edited, only revoked and replaced). REST API returns 404 on a specific record The id belongs to a different organisation, or doesn't exist / was soft-deleted. EDI export button stays disabled Both a "since" and "until" date are required before the button activates. EDI download link doesn't work Links expire 7 days after generation — run a fresh export. SFTP test fails at "tcp-connect" Host/port unreachable from HousingSurvey Pro's servers (europe-west2) — check the host, port, and any IP allowlist on your side. SFTP test fails at "handshake" with a fingerprint mismatch Your server presented a different host key than the one previously pinned — verify the new fingerprint with your IT team out-of-band before re-pinning; never re-pin on trust alone. SFTP test fails at "auth" Wrong username/password, or the public key isn't installed (or was removed) in the server account's authorized_keys . SFTP test fails at "stat-remote-path" The configured remote path doesn't exist, or the account can't access it. SMTP test doesn't arrive Wrong host/port/security (TLS vs STARTTLS on the wrong port is the most common cause), or a mail provider blocking unfamiliar app passwords — check your provider's own sent-mail log if available, and your spam folder. AI test fails with a provider error Usually an invalid/expired key, or billing not enabled on the provider account — the error message returned is the provider's own, only shortened for display. ### Residency & auditing All test and production traffic for these integrations is served from europe-west2 (London) — no test call ever leaves that region. Every API read/write and every webhook delivery attempt is written to your organisation's append-only, hash-chained audit log, so a test event and a production event are both fully traceable after the fact. See also: [Integrations — Webhooks & API](https://housingsurvey.pro/legal/help/integrations-api/) for the full API/webhook reference, [Integrations — AI provider keys](https://housingsurvey.pro/legal/help/integrations-ai/) for AI setup, or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Integrations — Single Sign-On (Microsoft Entra ID) Source: https://housingsurvey.pro/legal/help/integrations-sso/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Integrations — Single Sign-On (Microsoft Entra ID) # Integrations — Single Sign-On (Microsoft Entra ID) ProSurvey Apps Limited (company no. 17118570) · Help centre Connect HousingSurvey Pro to your organisation's identity provider so staff sign in with their existing corporate credentials. Tiered — Basics for what SSO gives you, Deep dive for setup, Technical for administrators and integrators. ## Basics — what SSO does - Staff sign in with their work identity (Microsoft Entra ID) instead of a separate password. - Access follows your directory — when someone leaves and is disabled in your IdP, their access here goes too. - It's optional, and applies to email/staff accounts; field surveyors without email use tenant logins instead (see [app sign-in](https://housingsurvey.pro/legal/help/app-signin/)). ## Deep dive — connecting Entra ID Setup is done by an org admin under Settings → SSO & provisioning : - In your Microsoft Entra admin center , register HousingSurvey Pro as an enterprise application. - Provide the details the Settings page asks for (tenant/directory and application identifiers) and the redirect URL shown on that page. - Assign the users or groups who should have access. - Save the connection in HousingSurvey Pro and test a sign-in. Keep at least one org-admin able to sign in by other means while you set SSO up, so you're never locked out mid-configuration. ## Technical — for IT / identity admins - Standards: SSO federates your IdP into the platform's identity layer (Firebase Auth / Identity Platform), which brokers the OIDC/SAML connection with Entra ID. - Provisioning: users are matched/created on first successful sign-in; automated user lifecycle (SCIM-style provisioning/deprovisioning) is on the roadmap — until then, disabling a user in your IdP prevents new sign-ins. - Multi-tenancy: a person can belong to more than one HousingSurvey Pro organisation; SSO governs the staff sign-in for organisations that enable it. - MFA: enforce MFA at your IdP; the platform also supports app-level TOTP. - Session control: an admin can revoke a user's sessions (remote logout) from the dashboard. Rollout note: SSO configuration and automated provisioning options are being delivered under the settings/provisioning track — confirm current availability on your Settings → SSO page. Next: [Integrations — AI provider keys](https://housingsurvey.pro/legal/help/integrations-ai/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Integrations — SFTP | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/integrations-sftp/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Integrations — SFTP # Integrations — SFTP ProSurvey Apps Limited (company no. 17118570) · Help centre For housing systems that exchange files rather than calling an API — the way a lot of housing IT actually works. HousingSurvey Pro connects out to a server your team already runs and controls; it is never a listener you connect into. Tiered — Basics for what's possible, Deep dive for setup, Technical for developers and integrators. ## Basics — connecting your systems - SFTP lets HousingSurvey Pro send files to your server (EDI exports, survey/works-completed/letter PDFs, invoices, your tenancy register) and pull specific data types from your server (property/UPRN stock, SOR repair-rate schedules, tenancy records), all over a standard SFTP connection to a server your IT team already runs. - You stay in control of the server the whole time — there's nothing to install on your side beyond adding one public key (or a password) to an account you already manage. - Configured under Settings → SFTP servers by an org admin. SFTP is a Platform-tier feature — the same tier as the REST API, webhooks and EDI exports it's typically used alongside. ## Deep dive — setting up - Add a server: Settings → SFTP servers → Add server . Enter the host, port, username and where files should land (remote path). You can add as many server entries as you need — one per housing system, one per environment, whatever fits how your IT team organises things. - Authentication: SSH key (recommended) or password, or both. If you choose a key, HousingSurvey Pro mints the keypair for you — click Mint key and you're shown the public half once, with the exact line to add to your server's authorized_keys . The private key is generated and stays on HousingSurvey Pro's backend; it is never shown again and never travels anywhere else. - Test connection: runs a real handshake, authentication and a read-only check of the remote path — it never writes a file. The first successful test shows your server's host-key fingerprint; confirm it matches what your IT team expects, then pin it. From then on, if that server ever presents a different key, every connection is refused until someone re-confirms it — this catches both a legitimate re-key and a compromised/intercepted connection, and treats both the same way until a human looks at it. - Sending things: once a server is configured, a Send to SFTP option appears next to survey reports, works-completed records, resident letters and (for platform invoicing) invoices — pick the destination at the point you send, no separate setup needed. EDI exports can instead be configured to deliver automatically to a chosen server every night, alongside the existing download/link delivery (SFTP is additional, not a replacement — the usual export is never blocked by an SFTP problem). - Pulling things in: under a server's Inbound imports , set a folder path for property/UPRN stock, SOR schedules and/or tenancy records, then Pull now . This previews what would happen — files found, rows to create/update, anything that failed to parse — without writing anything. Confirm only after reviewing the preview, and it double-checks the files on your server haven't changed in the meantime before writing anything. For tenancies specifically: a row matches by tenancy reference when your housing system supplies one, otherwise by property + tenant name; a row that can't be matched to a property still imports, flagged for manual review. - Sending your tenancy register: from the Tenancies tab (alongside Properties), Send to SFTP builds a fresh CSV of your whole register and delivers it to a chosen server the same way any other outbound file does. ## Technical — for developers & integrators - Client only: HousingSurvey Pro never listens for inbound SFTP connections. It is a client of your server, using the ssh2 library over a standard SFTP session. - Keys: ed25519 by default, RSA-4096 available for servers that don't support ed25519. Each server entry has its own keypair — there is no shared or organisation-wide key. Re-minting a key for an entry replaces it; remove the old public key from authorized_keys once the new one is installed. - Host-key pinning: trust-on-first-use, fail-closed. Once pinned, a fingerprint mismatch aborts the connection before authentication — no file is ever read or written on a mismatch. - Outbound writes: every file is written to a temporary, hidden name in the target directory first, then renamed into its final filename — a process watching that folder never sees a partially-written file under the real name. - Inbound scope: CSV only, three data types — property/UPRN stock, SOR repair-rate schedules, and tenancy records — reusing the same validation rules as their existing manual-upload importers. There is no scheduled/automatic pull; every inbound transfer is a manual action. - Activity & audit: every test, delivery and pull is logged to your organisation's SFTP activity feed (visible to manager-level users and above), with the specific failed step named on any failure — nothing fails silently. Rollout note: the set of things HousingSurvey Pro can send and pull over SFTP may grow over time; the security model (per-server keys, private key custody, fail-closed fingerprint pinning) is fixed. Confirm what's currently supported on your Settings → SFTP servers page. Back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Integrations — Webhooks & API | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/integrations-api/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Integrations — Webhooks & API # Integrations — Webhooks & API ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [Basics — connecting your systems](#basics-connecting-your-systems) - [Deep dive — setting up](#deep-dive-setting-up) - [Technical — for developers & integrators](#technical-for-developers-integrators) - [Handling report versions](#handling-report-versions) For teams that want to connect HousingSurvey Pro to their own systems — a housing management system, a data warehouse, a BI tool — the platform offers event webhooks and a programmatic API . Tiered — Basics for what's possible, Deep dive for setup, Technical for developers and integrators. ## Basics — connecting your systems - Webhooks push a notification to your endpoint when something happens (a survey is sealed, a work order changes stage), so your systems react in real time instead of polling. - API lets your systems read data (properties, surveys, work orders) and, on higher tiers, drive workflows programmatically. - Both are configured under Settings → API & webhooks by an org admin, and are available on the appropriate plan tier. ## Deep dive — setting up - API keys: generate a key in Settings → API & webhooks. Treat it like a password — it grants access scoped to your organisation. Rotate or revoke keys at any time; revoking is immediate. - Webhook endpoints: register the HTTPS URL your system listens on and select the events you care about. Each delivery is signed so you can verify it genuinely came from HousingSurvey Pro. - Testing: every integration on this page has a self-serve test — send a signed test webhook event, run curl against the API with a sample payload viewer, trigger a one-off EDI export, and more. See [Integrations — Testing your connection](https://housingsurvey.pro/legal/help/integrations-testing/). ## Technical — for developers & integrators - Auth: API requests authenticate with your organisation-scoped API key; every call is checked against the same server-side security rules as the UI, so an integration can never exceed your organisation's data boundary. - Webhook security: deliveries are signed (HMAC over the payload with your secret); verify the signature and reject anything that doesn't match. Handle retries idempotently — treat repeated event IDs as one. - Data model: the API exposes the same tenant-scoped entities described in [Access control](https://housingsurvey.pro/legal/technical/access-control/); evidence remains immutable and hash-chained regardless of how it's read. - Residency & limits: calls are served in-region (UK); rate limits and the full event catalogue are documented on the Settings → API & webhooks page. ### Handling report versions A finalized report can later be revised : the original sealed record is never edited in place — a new sealed record is created that supersedes it. Every version, old and new, stays retrievable and independently hash-chained; nothing is ever overwritten. - lineageId is stable across every version of a report — it's the original record's own id. Key your stored reports by lineageId . - versionNo is 1-based and increments with each revision. Treat the highest versionNo you've seen for a lineageId as the current version. - supersedes holds the id of the version this one replaces — null on the original (version 1). - All three fields appear on the survey.finalized webhook payload, on every survey returned by GET /v1/surveys and GET /v1/surveys/:id , and as version_no / supersedes columns in the nightly EDI CSV export. Example survey.finalized webhook body for a third version of a report: { "event": "survey.finalized", "orgId": "org_4b7e1a", "at": "2026-07-09T08:12:44.000Z", "surveyId": "svy_1e88bb", "recordHash": "3f9e2c1a7b…", "chainSeq": 12, "lineageId": "svy_9f2a01", "versionNo": 3, "supersedes": "svy_c77d40", "estimatedCosts": { "total": 450, "currency": "GBP", "itemCount": 2 } } Rollout note: the API surface and webhook event catalogue are expanding; the auth model (org-scoped keys, signed deliveries, rules-enforced access) is fixed. Confirm currently available endpoints and events on your dashboard. Back to the [help index](https://housingsurvey.pro/legal/help/). This completes the help-centre core; every dashboard section and app module now has a guide. [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Integrations — AI Provider Keys | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/integrations-ai/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Integrations — AI Provider Keys # Integrations — AI Provider Keys ProSurvey Apps Limited (company no. 17118570) · Help centre HousingSurvey Pro's AI features run on your own AI provider account and key. There is no shared platform key — you're in control of the provider, the cost, and the data-processing terms. Tiered — Basics to switch it on, Deep dive for what AI does, Technical for administrators. ## Basics — turning AI on - Open Settings → AI (org admin). - Choose your provider (e.g. Anthropic, OpenAI, Azure OpenAI, Google) and paste your own API key . - Save. AI-assisted features light up across the app and dashboard. With no key configured, AI features are simply off — the platform "fails closed". Nothing AI-related happens without your explicit key. ## Deep dive — what AI does (and doesn't) AI in HousingSurvey Pro is advisory and drafts-only : - AI Polish — tidies a surveyor's dictated or typed notes into clear report wording. - Photo analysis — describes what's visible in a defect photo to assist the surveyor. - Repair-code suggestions — from a defect photo, suggests codes from your own SOR catalogue (the model never sees or invents rates). - Summaries — drafts an executive summary the surveyor reviews. What AI never does: - It never enters evidence on its own — a human always reviews and commits. - It never computes the compliance assessments — HHSRS, condensation and IAQ are calculated by deterministic engines, not a model. ## Technical — for administrators - Bring-your-own-key: the platform uses your provider account, so AI processing occurs under your agreement with that provider. Rotate or revoke the key anytime in Settings → AI. - Fail-closed: no key ⇒ AI off. There is no silent fallback to a platform key (there isn't one). - Providers: Anthropic, OpenAI, Azure OpenAI, Google, or a compatible BYO endpoint. Vision (photo) features require a vision-capable model. - Data: only the specific text/image for a requested action is sent to your provider; assessment maths and evidence sealing happen in-platform. - Cost control: because it's your key, usage and spend are visible in your provider's dashboard and governed by your own limits. Rollout note: the set of AI-assisted surfaces continues to grow; the bring-your-own-key, advisory-only, fail-closed model is fixed and applies to all of them. Next: [Integrations — Webhooks & API](https://housingsurvey.pro/legal/help/integrations-api/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Getting Started | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/getting-started/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Getting Started # Getting Started ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [Basics — your first 20 minutes](#basics-your-first-20-minutes) - [1. Create your organisation](#1-create-your-organisation) - [2. Add your property stock](#2-add-your-property-stock) - [3. Invite your team](#3-invite-your-team) - [4. Raise work and survey a property](#4-raise-work-and-survey-a-property) - [5. Generate a report](#5-generate-a-report) - [Deep dive — configuration you'll want next](#deep-dive-configuration-youll-want-next) - [Technical — for IT managers & integrators](#technical-for-it-managers-integrators) Welcome to HousingSurvey Pro. This guide gets a new organisation from sign-up to a first completed survey. It is written in tiers — read the Basics to get going; open Deep dive and Technical only if you need them. ## Basics — your first 20 minutes ### 1. Create your organisation - Go to the management dashboard and choose Create organisation . - Enter your organisation name and confirm you are a landlord (housing association) or a contractor. Landlords own the evidence; contractors work against it. - You are now the first org admin . ### 2. Add your property stock - Open Properties → Import . - Download the example file, fill it in (address line 1 and postcode are the minimum), and upload it as CSV or Excel (.xlsx) . - Review the preview — any skipped rows are listed with the reason — then confirm the import. Re-importing the same UPRN updates, never duplicates. ### 3. Invite your team - Open Settings → Members (or Team ). - Invite colleagues by email for office/manager roles. - Field surveyors without email get a tenant login (username/code + passcode) provisioned here — they use it to sign in on the mobile app. ### 4. Raise work and survey a property - Create a Work order for a property (or let an Awaab's Law damp-and-mould case drive it). - Assign it to a surveyor. They receive it in the mobile app's jobs inbox. - The surveyor drives to the property, captures the survey on-site, and finalises it. The sealed evidence appears back in Evidence on the dashboard. ### 5. Generate a report - Open the survey in Evidence and choose Report . - The branded, print-ready report is generated from the sealed evidence — use your browser's print/PDF to save or send it. ## Deep dive — configuration you'll want next - Branding (Settings → Branding): upload your logo and set accent colours; these flow into the surveyor app and reports. - Capture policy (Settings): require on-site GPS editing, set the survey radius, choose which optional modules (e.g. estimated costs) are enabled, and set currency and temperature units. - Repair rates (SOR): import your licensed Schedule of Rates catalogue so work-order costing and photo-to-code suggestions switch on. - Compliance schedule (Settings): review the indicative Awaab's Law timeline (investigate / written summary / begin works) and adjust to your policy — it is a planning aid, not a legal guarantee. - Permissions : assign each member a role baseline, then use per-module None/View/Edit/Module-admin overrides where needed. Platform system admin and owner-only powers cannot be granted this way. ## Technical — for IT managers & integrators - SSO: connect Microsoft Entra ID for staff sign-in (Settings → SSO & provisioning). See Integrations — SSO (in the help index). - AI provider key: HousingSurvey Pro uses your own AI provider key (Anthropic/OpenAI/Azure/Gemini). Add it in Settings → AI; with no key, AI features are simply off. AI output is advisory and never enters evidence. - API & webhooks: programmatic access and event webhooks are configured under Settings → API & webhooks. - Data residency & security: data is hosted in London (europe-west2); evidence is hash-chained and tamper-evident. See the [Security & data architecture](https://housingsurvey.pro/legal/technical/security-architecture/) page. - Exports: full-organisation and GDPR subject-access exports are available to admins (Settings → Data & exports). Next: pick your area from the [help index](https://housingsurvey.pro/legal/help/) — every dashboard section and every app module has its own page. [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## The Live Demo — a 20-Minute End-to-End Tour | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/demo-walkthrough/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / The Live Demo — a 20-Minute End-to-End Tour # The Live Demo — a 20-Minute End-to-End Tour ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [What you'll see (and what you won't)](#what-youll-see-and-what-you-wont) - [Step 1: Enter the demo (2 minutes)](#step-1-enter-the-demo-2-minutes) - [Step 2: Tour the Dashboard (5 minutes)](#step-2-tour-the-dashboard-5-minutes) - [Needs attention](#needs-attention) - [Stat tiles](#stat-tiles) - [Compliance & deadlines](#compliance-deadlines) - [What you can do](#what-you-can-do) - [Step 3: Raise two work orders (4 minutes)](#step-3-raise-two-work-orders-4-minutes) - [Raise an Awaab's Law damp & mould case](#raise-an-awaabs-law-damp-mould-case) - [Raise a general job](#raise-a-general-job) - [Step 4: Open the Field App & Capture Evidence (6 minutes)](#step-4-open-the-field-app-capture-evidence-6-minutes) - [Option A: In your browser (fastest for this demo)](#option-a-in-your-browser-fastest-for-this-demo) - [Option B: On your device (real app)](#option-b-on-your-device-real-app) - [Capture a survey (both browser and app paths):](#capture-a-survey-both-browser-and-app-paths) - [Step 5: Verify the Sealed Record (2 minutes)](#step-5-verify-the-sealed-record-2-minutes) - [Sealed record details](#sealed-record-details) - [Verify the hash (optional but powerful)](#verify-the-hash-optional-but-powerful) - [Step 6: Export the Record (1 minute)](#step-6-export-the-record-1-minute) - [JSON export](#json-export) - [CSV export](#csv-export) - [Step 7: Fire the Echo Webhook Test (1 minute)](#step-7-fire-the-echo-webhook-test-1-minute) - [Step 8: Invite a Colleague (1 minute)](#step-8-invite-a-colleague-1-minute) - [End of tour](#end-of-tour) - [What to try next](#what-to-try-next) - [Demo limitations (what's pending)](#demo-limitations-whats-pending) A fully-functional damp & mould evidence capture system, live and free on the public internet — no sign-in card, no 30-day trial timer, no feature unlock. Every visitor gets a private sandbox: your own organisation, your own properties, your own sealed records. Work is yours until you refresh; refresh deletes it cleanly (the system's demo model, not a limit). This page walks you through one complete cycle: enter the demo, explore the dashboard, raise and assign work orders, capture evidence in the field, finalise the record, verify the chain, and export it. ## What you'll see (and what you won't) Full E2E demo in the browser: - Dashboard with Awaab's Law real-time clock and case-note evidence - Work order creation, assignment and tracking - Field app in your browser (full capture: GPS, photos, readings, AI-assisted narrative drafts) - Record finalization and sealing - Sealed-record verification and export (JSON/CSV) - Webhook test-fire to your own endpoint Deliberately absent (and that's OK): - Offline persistence (the demo is browser-only, no device storage) - Native camera access (file picker instead — same evidence, different device path) - Speech-to-text (type instead) - Stripe integration or billing (demo orgs can't upgrade) - Real email sends (the echo webhook shows what would have been sent) The field app's browser build, the core evidence engine, and every data path are production-identical. The only difference is reach — offline and device APIs — not depth. ## Step 1: Enter the demo (2 minutes) - Go to https://demo.housingsurvey.pro , our demo environment. - You'll see the landing page. Look for the "Try the live demo" CTA (usually in the hero or a prominent call-to-action section). - Click it. The system will: - Create a private demo organisation for you - Sign you in anonymously (no email needed) - Mint a surveyor account with temporary credentials - Show you a demo banner with those credentials Save those credentials. You'll use them in Step 4 to sign into the field app. ## Step 2: Tour the Dashboard (5 minutes) You're in the portal now — the housing association's management view. Top to bottom, the dashboard shows: ### Needs attention A compact amber panel unions three triage signals into one place: statutory deadlines that are overdue (a jump-link to the full list below, rather than duplicating rows), work orders nobody's assigned yet, and visits that were scheduled but never marked complete. Collapses to a single "All clear" line the moment there's nothing to chase. Click any row to jump straight into that work order's drawer. ### Stat tiles Evidence records / Finalized (locked) / Drafts in field / Damp-mould hazards / Overdue / Due soon — each one a live count, each one clickable through to the filtered Evidence or Work orders list behind it. ### Compliance & deadlines The full statutory board, grouped Overdue / Due soon / an expandable on track / an expandable resolved — each work order's own row shows the property, the deadline it's tracking (investigate / written summary / begin works) and how many days over or until due. This is the core of Awaab's Law compliance — not a report, not an export, just your live case backlog tracked against fixed timescales, every deadline computed server-side. ### What you can do - Click a work order (from the Needs attention panel or the board below) to open its details, add case notes, and track its lifecycle. - Open Work orders from the sidebar to create a new one, or to filter the full list by status, bucket, or the Overdue quick-filter chip. ## Step 3: Raise two work orders (4 minutes) Create one Awaab's Law case and one general job to show the system's range. Only Property address and Description are required (marked with a plain \ *) — everything else defaults sensibly, and two sections collapse behind optional disclosures you can leave closed for this walkthrough. ### Raise an Awaab's Law damp & mould case - Open Work orders from the sidebar and click Create . - Fill in: - Property address : pick one from the list (the demo has pre-seeded properties), or type a new one. - Description : "Visible damp in bedroom — tenant report" - Job type : leave on the default, "Awaab's Law — damp & mould" — its hint tells you the statutory clock this stamps (investigate within 10 working days). - Click Create . The work order is now live with an immediate Awaab's Law statutory deadline. ### Raise a general job - Click Create again. - Fill in a different property and description, then switch Job type to "General / routine" — its hint confirms this carries no statutory clock, just a due date you set yourself. - Click Create . (Optional, while you're here: open "Add report details (optional)" to see the case-detail fields for the report — tenant contact, reference number, scope of survey — or "Assign now (optional)" to schedule a visit or send straight to a contractor. Both stay closed by default; the minimal path is genuinely just address + description + Create.) Back on the dashboard, both work orders now appear in the Work orders list. The Awaab's Law case also carries a real countdown on the Compliance & deadlines board (its statutory clock is always on); the general job only joins that board too if your organisation has opted into its own internal target dates (Settings) — the demo org doesn't by default, so it's tracked on the Work orders list alone. This is the real difference between statutory and routine damp work in UK social housing. ## Step 4: Open the Field App & Capture Evidence (6 minutes) Now you'll sign into the surveyor app and capture evidence against one of the work orders. ### Option A: In your browser (fastest for this demo) - In the portal, click the "Try the field app" or demo banner link (or navigate to https://app-demo.housingsurvey.pro ). - Sign in with the credentials shown in the demo banner: surveyor@[your-demo-org].demo.local and the shown password. - You're in the app. Tap My survey jobs or the work order list. ### Option B: On your device (real app) If you want to test the real iOS/Android experience: - Install the HousingSurvey Pro app from the App Store (iOS) or Play Store (Android) — it's free. - Sign in with those same demo credentials. - The same work orders appear; full offline capture is supported. ### Capture a survey (both browser and app paths): - Tap a work order to open it. - The system checks your GPS location. In a demo, this is simulated (or your actual browser location); either way, the system records it. - You'll see the property details (address, type, occupancy, previous surveys if any). - Tap Start survey to open the full wizard. The wizard is broken into sections: - Rooms (damp observations per room) - Atmospheric (humidity, temperature readings — simulated or from your device) - Damp & observations (severity, visible defects, cause assessment) - Externals (roof, walls, drainage) - Ventilation (fan status, air quality) - Soil & drainage (fetches real ISRIC data if near the property; demo uses fallback data) - Photos (tap to add or pick from device; browser shows file picker) - Narrative sections (auto-generated from findings + your own text) - Sign-off (surveyor name and accreditation) Complete one section (e.g. Damp & observations ): - Enter a severity (e.g. "Moderate active condensation") - Add observed issues (e.g. "Mold on north wall, no extraction fan") - Tap the ✨ AI Polish button to let the system refine your notes into professional language. - Photos: add one photo per issue (can skip for the demo — the system works without them) Once you've filled a couple of sections, tap Finalise at the bottom. The system will: - Lock your entries (read-only going forward) - Compute the record hash (SHA-256, chained to any prior records for this property) - Server-stamp the completion time - Create an append-only audit log entry Note : If photos are still uploading, you'll see an amber banner — wait a moment or manually sync, then try finalising again. ## Step 5: Verify the Sealed Record (2 minutes) Back in the portal (refresh if needed), click the same work order. You'll see: ### Sealed record details The Survey section now shows: - Read-only view of every captured field (rooms, photos, readings, narrative) - The completion timestamp (server-authoritative, sealed at finalize) - The record hash (64-character SHA-256) - Previous record for this property (if any) — shows the prevHash chain link - Audit log link (shows every read/write ever, immutable) ### Verify the hash (optional but powerful) The hash is proof of tamper-evidence: - Scroll to Record details . - Copy the Record hash value. - Download the full survey JSON (see next step — "Export"). - Run the verification tool (outside this demo) — any change to any field will produce a different hash. In practice, your case-management system does this automatically on ingest. For now, the hash itself is the anchor: change one reading, one photo metadata, one word of narrative, and the hash changes. Store it alongside your evidence — if the ombudsman ever asks "could this have been edited?", the hash is your answer. ## Step 6: Export the Record (1 minute) ### JSON export - In the sealed-record view, click Export → JSON . - The browser downloads the full survey-{id}.json — every field in its sealed form. - Open it in a text editor to see the structure: properties, rooms, readings, photos (as URLs), AI provider context, signature, lifecycle dates, the hash itself. This is the same shape your REST API integration receives when a real survey finalises. Build your ingest parser against this. ### CSV export - Back in the portal, go to Settings → API & webhooks → EDI flat-file (CSV) . - Pick a date range that includes your new survey. - Click Export CSV . - The download is a flat file (one survey per row, key fields only) — the format your CMS ingest might prefer. ## Step 7: Fire the Echo Webhook Test (1 minute) To see what a real webhook delivery looks like: - In the portal, go to Settings → API & webhooks → Webhook . - Scroll to Send test event (there's a pre-filled demo webhook URL). - Click Send test event . In ~1 second, you'll see: - Green, "Delivered · HTTP 200 · 45ms" — the test fired to the echo webhook service - A collapsed View sample payload section showing the exact JSON and signature headers The payload is marked "sample": true (not a real finalize event) but the signature is real — keyed with your org's real signing secret using the production HMAC code path. What's in the payload? - event : "test.ping" (test marker) - survey : the full JSON shape (same as the export above) - property : the linked property record - workOrder : the linked work order - organisation : your org's own metadata Your CMS webhook receiver would: - Verify the signature (compare x-hsp-signature header to HMAC of the raw body) - Check the "sample": true flag and log/discard it (or route to a test log) - On a real survey.finalized event, ingest the record into your case store ## Step 8: Invite a Colleague (1 minute) Demo orgs are capped at 2 surveyor seats (a paid seat class everywhere, free here too) — managers, coordinators and other office roles are free and uncapped on every real plan. Let's add one: - Go to Settings → Members & seats . - Click Invite . - Enter an email address (any address — the demo email system sends nothing; you'll see a preview instead). - Pick a role: "Surveyor" (capture only) or "Manager" (case oversight + work-order assignment). - Click Send invite . In a real org, the invite would email a sign-in link. In the demo, the screen shows a preview of what the invite would look like. That colleague can now: - Access the same work orders (as a surveyor) and see your sealed records - Contribute their own surveys - Build the evidence chain for this property together ## End of tour You've walked through: - ✅ Portal entry and anonymous onboarding - ✅ Awaab's Law statutory deadline tracking - ✅ Work-order creation (Awaab's Law + general) - ✅ Field capture (browser and device apps) - ✅ Record finalization and server-sealing - ✅ Hash-chained evidence verification - ✅ Export (JSON, CSV) - ✅ Webhook integration (test-fire) - ✅ Team collaboration (invite a seat) This is the complete flow. Every step — from case creation to sealed record to CMS ingest — is production code running on live infrastructure, just in a private sandbox that resets. ## What to try next - Test offline: Install the app on your device, capture a survey, disconnect from the internet, and re-open it — the app keeps working, syncs on reconnect. - Test integrations: Set up a webhook URL on your own server (use [Webhook.cool](https://webhook.cool) or similar if you don't have one handy), paste it into Settings → API & webhooks , and send a test — see the exact signature and payload shape your system will receive. - Explore the data model: Export JSON and explore the nested shape — this is exactly what the REST API and Power Automate connector expose. - Read the handbook: If you're a manager setting up the real thing, start with [Getting started](https://housingsurvey.pro/legal/help/getting-started/); if you're integrating, see [Integrations — API & webhooks](https://housingsurvey.pro/legal/help/integrations-api/). ## Demo limitations (what's pending) The demo runs on the same code and Firestore as the production system. The only known gaps: - Offline persistence: The browser app can't cache surveys to IndexedDB the way the native app does on your device. Work offline on a real device; demos are always online. - Photo compression: The demo file picker shows full-res photos. The production app compresses them (1280px, 70% quality) before upload — stored photos are much smaller. - Email send: The system logs what would have been sent (e.g. statutory deadline reminders, invitation emails) but doesn't actually send anything — no spam, no real addresses harvested. - Stripe billing: Demo orgs can't upgrade to paid plans or add seats beyond the cap. The real system does this via your card on the Pricing page. - DNS custom domains: The demo runs at https://demo.housingsurvey.pro and https://app-demo.housingsurvey.pro . Everything else works exactly as it would in your own production org. Questions? Start at [Getting started](https://housingsurvey.pro/legal/help/getting-started/), check the full [help index](https://housingsurvey.pro/legal/help/), or reach us at founders@housingsurvey.pro. [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — Work Orders & Awaab Timeline Source: https://housingsurvey.pro/legal/help/dashboard-workorders/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — Work Orders & Awaab Timeline # Management Dashboard — Work Orders & Awaab Timeline ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [Basics — raising and tracking work](#basics-raising-and-tracking-work) - [The work-order drawer](#the-work-order-drawer) - [Deep dive — the Awaab timeline & costing](#deep-dive-the-awaab-timeline-costing) - [The indicative Awaab's Law timeline](#the-indicative-awaabs-law-timeline) - [Repair costing (Schedule of Rates)](#repair-costing-schedule-of-rates) - [Works Orders & Sealed Remediation Records](#works-orders-sealed-remediation-records) - [Resident letters, every case stage](#resident-letters-every-case-stage) - [Access attempts — field and office-logged](#access-attempts-field-and-office-logged) - [Offline & GPS — how it actually works](#offline-gps-how-it-actually-works) - [Technical — Notifications & Tracking](#technical-notifications-tracking) - [Technical — how it's computed](#technical-how-its-computed) Work orders are how you dispatch remedial work and track it against the indicative Awaab's Law timeline. Tiered — Basics for the everyday flow, Deep dive for costing and the statutory clock, Technical for how it's computed. Looking for the case's overall position — Raised through to Closed, and the honestly-labelled alternatives for summary, photo, presence, and verification — see [The lifecycle, end to end](https://housingsurvey.pro/legal/help/dashboard-lifecycle/). This page focuses on the works arc specifically. ## Basics — raising and tracking work - Open Work orders from the sidebar. - Create a work order — only Property address and Description are marked required (a plain \ *); everything else defaults sensibly. Case-detail fields for the report (tenant contact, report title/type, reference number, scope of survey) sit behind an "Add report details (optional)" disclosure, and scheduling a visit or sending straight to a contractor sit behind a separate "Assign now (optional)" disclosure — open either only if you need it; the minimal path stays address + description + Create. - Assign it — to an internal surveyor, or to a contractor organisation you have a grant with. - Track its stage as it progresses; the assigned party updates status as they investigate, make safe, and complete works. The Dashboard 's "Needs attention" panel surfaces overdue, unassigned and stalled cases in one place (a jump-link takes you to the full overdue list below it); the work-order list itself has its own Overdue (N) quick-filter chip alongside the status/bucket filters. - When a survey is raised for the order, its sealed evidence links back here. ### The work-order drawer Opening a work order shows a tabbed drawer — Overview , Letters & PDFs , Timeline , Assignment & costs — auto-opened to whichever tab matches the case's current stage. All four stay loaded in the background as you switch, so a half-written letter draft or a form you were filling in survives a tab change. Letters & PDFs holds every resident-letter card this case can show right now (see Resident letters, every case stage below); Timeline holds notes, follow-ups, linked evidence and access attempts (including the Awaab's Law statutory clock and written-summary letter for a survey-kind case); Assignment & costs holds who it's assigned to and, where applicable, repair costing. ## Deep dive — the Awaab timeline & costing ### The indicative Awaab's Law timeline For a damp-and-mould case, the dashboard shows an indicative timeline with stages counted from a date you choose: - Investigate the hazard — within ~10 days. - Written summary to the resident — a few days later. - Begin repair works — shortly after. Each stage shows a countdown and an urgency state ( on track , due soon , overdue ). A presence check-in on site stamps when works began. Important: this is a planning aid, not a compliance guarantee . Awaab's Law timescales apply to social housing in England, are counted in working days , and are being phased in; this tool counts calendar days from your chosen date. Review and edit the schedule to your policy in Settings before relying on it. ### Repair costing (Schedule of Rates) If you've imported your SOR catalogue (see Repair rates ), a work order gains a costing section: - Search your codes by prefix or plain-English keyword (e.g. "sealant"). - Add lines with quantities; the estimated total updates live. - From a defect photo, get AI-suggested codes from your own catalogue with quantity estimates — always reviewed before adding. ### Works Orders & Sealed Remediation Records Work orders close the statutory loop by capturing proof of completion. Here's the full cycle: 1. Create works from a survey From an Evidence record, select specific hazards (damp findings, etc.) and create a works order . The works order links to the original survey and records which hazards it will remediate. 2. Assign to operatives or contractors Assign the works order to an operative (a field worker — staff, subcontractor, or contractor-org member) who will perform the repairs. They receive a notification that a job is assigned. 3. Works in progress The operative sees the works job in their mobile capture app ( My works jobs ), including: - The original hazard photos and scope from the survey - A checklist of findings to remediate - GPS-verified location and scheduling details - Reminders as the due date approaches 4. Completion with photo evidence On site, the operative: - Takes after-repair photos (same GPS and fingerprint chain as survey photos) - Records their location (GPS fix) - Marks the job complete The system seals a remediation record — a tamper-evident document that proves the work was done, where, and when. It cryptographically chains back to the original survey , creating an unbroken audit trail: survey → works → sealed remediation proof. Photos can be made optional. If your organisation's capture policy turns off "Require photos for works completion" (Settings → Capture policy), a job can still be completed with zero photos , but a completion note becomes mandatory instead — the system will never accept a wholly empty seal. Those records carry a "Notes Only — No Photo Evidence" chip, so anyone reviewing the file later can see, at a glance, that this record is weaker evidence than the photographed default and honestly labelled as such. The setting is off by default — your organisation opts in deliberately. 5. Verification A coordinator or surveyor can raise a re-survey against the remediated property to verify the hazard is resolved. If the re-survey confirms the fix, the works order is marked verified — the strongest possible proof for regulators or the Housing Ombudsman. If a full re-survey isn't practical, a coordinator can instead verify by attestation — recording that they inspected and accepted the completed works on a site visit, with a mandatory reason — carrying a "Verified By Attestation — No Re-Survey" chip so the weaker path is never mistaken for a re-survey-confirmed one. Either route makes the case eligible to close ; see [The lifecycle, end to end](https://housingsurvey.pro/legal/help/dashboard-lifecycle/) for the full gate table and the closure reasons. Portal fallback: if an operative can't access the app, a coordinator can record work completion and upload evidence on their behalf (marked as proxy). A proxy completion carries no presence data — the coordinator isn't on site, so no GPS fix is captured or claimed for it; the record and its report show a "No presence data" indicator instead of a fabricated location. ### Resident letters, every case stage At each meaningful moment in a case — survey scheduled, investigation complete, the Awaab's Law written summary, works scheduled, works completed, an access attempt, case closed — the case detail offers a resident letter : a compose box that's always freely editable and an always-available Insert template button built deterministically from the job's own data (no AI required). Four of those moments also offer an optional Draft with AI starting point using your own AI key — survey scheduled , investigation complete (the cover note for the sealed report), the written summary (the Awaab's Law findings letter, on the Timeline tab alongside the statutory clock), and works scheduled . Works completed, case closed and access-attempt letters only ever offer the deterministic template — never fabricated either way, and every AI draft is always yours to review and edit before it goes anywhere. The From line defaults to whoever's sending it but stays editable. Once you're happy with the letter, Send emails it to the resident (a copy of the linked report or works-completed PDF is attached automatically where one applies), or use View PDF without sending. Print, Copy letter, and — on the Platform plan — Send to SFTP (the cover letter and, where one applies, its linked artifact) all sit one click away under Other outputs ; an organisation without SFTP on its plan simply doesn't see that option at all, rather than a locked/greyed one. A works-completed letter's PDF is kept with the job's evidence afterwards — Regenerate rebuilds and re-stores it if anything changes later. ### Access attempts — field and office-logged Every attempt to gain access for a visit is sealed, hash-chained evidence for Awaab's Law "reasonable attempts" records, shown on the drawer's Timeline tab. A field visit logs its own attempt from the capture app, GPS-anchored. A coordinator can also log an access attempt from the office — a call or report received off-site rather than a field visit — with a reason and an optional note; it's sealed the same tamper-evident way, but carries no GPS and is permanently, visibly marked "Office-Logged — No GPS" , at full prominence, never blended in with a field-verified attempt. The Timeline tab always shows an access-attempts control, even before any attempt exists, and its header honestly counts how many of the listed attempts were office-logged. The resident letter for an access attempt states the source in its body and only claims a visit was made when one genuinely was. ### Offline & GPS — how it actually works Operatives sometimes ask how GPS proof-of-completion is supposed to work with no signal on site — here's the short answer: - Satellite GPS needs no phone signal or data connection. Your device's GPS receiver gets its fix directly from satellites overhead, the same way offline turn-by-turn navigation works. A dead spot for calls/data doesn't stop a location fix. - Photos and the GPS fix are captured fully offline , saved to the device immediately. Nothing is lost if you're out of signal for the whole visit. - Sealing the record — the one step that writes the tamper-evident remediation record — needs a connection, because it's a server-authoritative action, not a queued write. If you're offline when you tap Complete , everything you captured stays safely on the device; reconnect and tap Complete again to seal it. - A desktop computer has no GPS hardware at all , so a location fix will never succeed there — that's expected, not a bug. GPS proof-of-completion is a field-device job; from a desk, use the portal's proxy-completion route instead (which, as above, records no presence data — it doesn't pretend the coordinator was on site). ## Technical — Notifications & Tracking The platform notifies team members at key moments: - Works assigned — assigned operative receives a push and in-app alert with job details. - Works reminder — a day before or on the scheduled date, a reminder push. - Works overdue — if a works job overshoots its due date and no completion is recorded, coordinators/managers/admins receive an in-app alert to investigate. All notifications are audit-logged and visible in your AlertCentre . ## Technical — how it's computed - Timeline: stage due-dates are computed from the trigger date and the effective schedule (per-survey override → org schedule → Awaab default), with calendar-correct date arithmetic. The engine is unit-tested and CI-gated. - Scheduling & dispatch: assignment can be assisted by travel-distance suggestions; on-site presence is captured via GPS check-in. - Costing: rates come from your own licensed SOR catalogue , tenant- private; the AI photo-to-code step uses your own AI key and a deterministic keyword ranker — rates are never invented by a model. - Permissions: costing is the landlord's to set; contractors can progress status but not rewrite ownership — enforced by security rules. Next: [The lifecycle, end to end](https://housingsurvey.pro/legal/help/dashboard-lifecycle/) for the full case spine and caveat gates, [Repair rates (SOR)](https://housingsurvey.pro/legal/help/dashboard-sor/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — Repair Rates (Schedule of Rates) Source: https://housingsurvey.pro/legal/help/dashboard-sor/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — Repair Rates (Schedule of Rates) # Management Dashboard — Repair Rates (Schedule of Rates) ProSurvey Apps Limited (company no. 17118570) · Help centre The Repair rates area is where you import your own licensed Schedule of Rates (SOR) catalogue. Once loaded, work-order costing and photo-to-code suggestions switch on. Tiered — Basics to import and browse, Deep dive for the file format and matching, Technical for how it stays tenant-private. ## Basics — importing your catalogue - Open Repair rates from the sidebar. - Click Example CSV to see the expected layout. - Export your catalogue from your M3/NHF tooling as CSV or Excel (.xlsx) . - Upload it. You'll see a per-row summary and any errors. - Add a version label (e.g. "M3NHF V8 · 2026 rates") so you know which edition is loaded. - Once imported, browse your codes by prefix or keyword. Your rates are yours — HousingSurvey Pro never ships, seeds, or shares a rate catalogue. You import your own licensed data. ## Deep dive — file format, matching & costing - Required columns: code, short description, unit, rate. Optional: medium description, trade. - Row validation: codes containing characters that can't key a record are rejected; duplicate codes keep the first and warn; missing required fields are listed with the row number. - Keyword search: find codes by prefix (e.g. XX1 ) or plain-English keywords (e.g. "sealant") — works with no AI configured. - Work-order costing: on a work order, search your codes, add lines with quantities, and the estimated total updates live. - Photo → suggested codes: from a defect photo, your own AI describes the likely repair tasks; a deterministic ranker matches those to your catalogue and suggests codes with quantity estimates. Everything is advisory — a human reviews before adding. ## Technical — licensing & isolation - Tenant-private: your catalogue is scoped to your organisation. Isolation is enforced by server-side security rules and verified by emulator rules tests in CI — another tenant can never read your rates. - Admin-write: only an org admin can import or amend the catalogue; managers and surveyors can read it for costing. - AI stays clean: the photo-to-code step uses your own AI key , and the model never sees or invents rates — it only describes visible tasks; the deterministic ranker does the code matching against your catalogue. - Formats: CSV and Excel .xlsx (legacy .xls unsupported — save as .xlsx /CSV). Parsers are unit-tested and CI-gated. Next: [Scheduling & dispatch](https://housingsurvey.pro/legal/help/dashboard-scheduling/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — Settings & Permissions | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/dashboard-settings/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — Settings & Permissions # Management Dashboard — Settings & Permissions ProSurvey Apps Limited (company no. 17118570) · Help centre Settings is the organised home for everything that configures your organisation — general details, branding, capture policy, integrations, notifications, and the permissions that govern who can do what. Tiered — Basics for common tasks, Deep dive for permissions, Technical for how it's enforced. ## Basics — the Settings sections Open Settings from the sidebar. It's grouped into sections so each thing has a clear home: - General — organisation name and profile. - Branding — logo and accent colours (these flow into the surveyor app and reports). - Capture policy — on-site GPS requirement and radius, which optional modules (e.g. estimated costs) are on, currency and temperature units, and whether surveyors may create their own reports. Every toggle here applies the moment you change it. - App configuration — which data-collection modules and report sections the field app and report show, the standard legal-disclaimer and scope-of-survey wording, the sign-off declaration, and an optional reference-number prefix. Unlike Capture policy's instant toggles, changes here are staged as a draft: an amber "Unsaved changes" bar appears with Save changes / Discard , and navigating away with unsaved edits prompts you to confirm first. - Integrations — SSO, AI provider key, API & webhooks, your own SMTP server (with an optional one-time fall back to the platform relay if it fails), SFTP servers (Platform plan), and a read-only mail log of every statutory email and resident letter sent from your organisation. - Notifications — what alerts your team receives. - Members / Team — invite colleagues, provision field logins, set role baselines and manage per-member module permissions. - Billing — plan, invoices, statements. - My account — your own sign-in security, plus the Appearance toggle (light / dark / follow system) that applies across the whole portal, for you specifically — not an organisation-wide setting. ## Deep dive — roles & permissions Every member has a role baseline . For a non-owner member, an authorised administrator can then tune each product module from None through Module admin : - System admin — platform-level operations. This is not an organisation role and cannot be granted through the permissions editor. - Owner — the organisation's ultimate account holder: everything org admin has, plus billing/deletion and the ability to transfer ownership. - Org admin — full control of your organisation, including settings, members and billing. - Manager — day-to-day operations. - Coordinator — office staff: raises work orders, schedules visits and keeps case notes, with read-only evidence and dashboards. No exports, deletions, settings or member changes. Free. - Finance — billing and invoices only, plus dashboards. Free. - Viewer — read-only evidence and dashboards. Free. - Surveyor — field-capture baseline for assigned work and surveys. - Operative — works-only baseline for assigned remedial jobs, completion and repair photos. Free seat class. Can be contractor, subcontractor or your own staff. - Contractor — scoped to work granted to their organisation. To review or change a member, open Members / Team , use that person's Manage action and open Granular permissions . The table shows every product area with its Role baseline , Per-user override , Effective permission and Effective scope . Choose Inherit role to remove an override, or select 0 None , 1 View , 2 Edit or 3 Module admin , then save. For example, a finance member can be explicitly given view access to Evidence while retaining their billing baseline. An upgrade outside the role baseline is labelled before saving. Surveyor and operative access to evidence, properties, work orders and scheduling always stays limited to assigned records. Explicit access to administrative or other non-record modules can apply across the organisation. Owner permissions are fixed, nobody can change their own permissions, and Module admin never means platform system admin. Onboarding & offboarding: invite or provision users here, and suspend or remove them with a full audit trail. A surveyor's device can be cut off centrally (remote logout). ## Technical — how it's enforced - Server-enforced: callable checks load the member's active status and current role for every privileged request, while Firestore and Storage rules evaluate the same server-written override document. A stale token or hidden button cannot preserve revoked access. - Assignment-aware files: photo paths identify their survey or work order; Storage rules resolve that record before permitting an append-only image upload. Legacy paths that cannot prove assignment reject new writes. - Server-only surfaces: members/roles, audit events, API keys and billing are never client-writable; changes go through audited server logic. - Identity: email, SSO (Entra ID), and tenant username/code logins all map to the same model — see [Access control](https://housingsurvey.pro/legal/technical/access-control/). - Mail log: Settings → Integrations keeps a per-organisation, read-only record of every statutory email and resident letter sent — recipient, status and delivery response — visible to managers, org-admins and owners. Granular permissions are live in production and nonproduction. Changes apply without waiting for the member to refresh a role claim; a signed-in screen may briefly show a loading state while the effective permission document resolves. Next: [Billing & invoices](https://housingsurvey.pro/legal/help/dashboard-billing/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — Scheduling & Dispatch | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/dashboard-scheduling/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — Scheduling & Dispatch # Management Dashboard — Scheduling & Dispatch ProSurvey Apps Limited (company no. 17118570) · Help centre The Scheduling area helps you allocate surveys and repair visits to the right person at the right time, and confirm they were on-site. Tiered — Basics for allocating work, Deep dive for the suggestions and presence, Technical for how it's computed. ## Basics — allocating work - Open Scheduling from the sidebar. - See upcoming and unassigned work in a calendar/lane view. - Assign a job to a surveyor or a contractor from the dispatch pool. - The assignee sees it in their mobile app inbox with the due date. ## Deep dive — smart suggestions & presence - Assignment suggestions. When allocating, the dashboard can suggest who to send based on practical factors such as travel distance to the property, so you're not sending someone across the region unnecessarily. - On-site presence. When a surveyor arrives, a GPS check-in records that they were at the property; for damp-and-mould cases this also stamps when works began, feeding the Awaab timeline. - Urgency at a glance. Emergency and overdue items are highlighted so the most time-critical work surfaces first. ## Technical — how it works - Suggestions use the property's location and the team's coverage to rank candidates; the final choice is always yours. - Presence is captured as a GPS event tied to the work order and, where relevant, the survey — part of the contemporaneous record. - GPS enforcement (surveyor app): where your organisation enables it, a survey can only be started and edited within a set radius of the property; leaving the radius locks editing. This is configured in Settings. - Permissions: who can assign, reassign, or dispatch is governed by the role/permissions model — see [Access control](https://housingsurvey.pro/legal/technical/access-control/). Rollout note: some GPS-enforcement and scheduling-policy options are configured per organisation and are rolling out — check your dashboard settings for current availability. Next: [Settings & permissions](https://housingsurvey.pro/legal/help/dashboard-settings/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — Properties & Imports | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/dashboard-properties/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — Properties & Imports # Management Dashboard — Properties & Imports ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [Basics — importing your stock](#basics-importing-your-stock) - [Deep dive — file format & matching](#deep-dive-file-format-matching) - [Technical — storage & search](#technical-storage-search) - [Tenancy register](#tenancy-register) The Properties area holds your property stock. It's the register surveys are raised against, and where you bulk-import from your housing management system. Tiered — Basics for importing and browsing, Deep dive for the file format and matching, Technical for how it's stored and searched. ## Basics — importing your stock - Open Properties → Import . - Click Example file to download a template. - Fill it in. The minimum is address line 1 and postcode ; UPRN, local authority, tenure and archetype are optional but recommended. - Upload it as CSV or Excel (.xlsx) . - Review the preview : the count of properties ready, and any skipped rows listed with the reason (e.g. missing postcode, duplicate UPRN). - Confirm the import. Done. Re-importing is safe. Rows are matched on UPRN — re-importing the same UPRN updates the property, it never creates a duplicate. ## Deep dive — file format & matching - Accepted formats: CSV and Excel .xlsx . Legacy .xls isn't supported — save as .xlsx or CSV first. - Header auto-mapping: column names are matched flexibly and case- insensitively. For example "address", "address line 1", "line1" and "street" all map to the first address line; "post code", "postcode" and "zip" all map to postcode. - Row validation: rows missing an address or postcode are skipped and listed. A UPRN with no digits is flagged. Duplicate UPRNs within one file keep the first occurrence and warn on the rest. - What each column is for: UPRN is the stable identity (and the merge key); local authority and tenure feed reporting and Awaab's Law context; archetype helps group similar construction types. ## Technical — storage & search - Identity: where a UPRN is provided it becomes the record key, so imports are idempotent (re-import = update, not duplicate). Properties without a UPRN are flagged for review. - Linkage: surveys can be linked to a property so evidence chains onto that property's timeline; a work order carries the property reference. - Search at scale: properties are indexed for prefix search on address, so large estates stay responsive. - Tenant-scoped: properties belong to your organisation only; isolation is enforced server-side. - Parsing: the CSV/Excel parsers (BOM handling, quoted fields, header aliasing, UPRN normalisation) are unit-tested and gated in CI. ## Tenancy register Alongside your property stock, Properties → Tenancies holds who lives where — tenant contact details, occupancy dates and status, linked to the property by UPRN or your own reference. It's a lean, operational register: no vulnerability or special-category data is stored here, and (unlike survey evidence) tenancy records are ordinary data, not sealed or hash-chained. - Add tenancies one at a time, or import a CSV : tenancy reference, UPRN, tenant name(s), contact email/phone, occupancy start and status. Re-importing on the same reference (or UPRN + name) updates the existing record rather than duplicating it; rows that can't be matched are flagged needs review rather than silently dropped. - Export the whole register as CSV at any time, or push it straight to your own SFTP server — see [SFTP](https://housingsurvey.pro/legal/help/integrations-sftp/) (Platform plan). - Raising a work order or drafting a resident letter for a property with a matching tenancy suggests that tenancy's contact automatically, so you're not retyping a name and email you've already recorded. Next: [Work orders & Awaab timeline](https://housingsurvey.pro/legal/help/dashboard-workorders/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — The Lifecycle, End to End Source: https://housingsurvey.pro/legal/help/dashboard-lifecycle/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — The Lifecycle, End to End # Management Dashboard — The Lifecycle, End to End ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [Basics — reading a case's position](#basics-reading-a-cases-position) - [Deep dive — flexibility with caveats](#deep-dive-flexibility-with-caveats) - [Survey-only and works-only cases](#survey-only-and-works-only-cases) - [The buckets, briefly](#the-buckets-briefly) - [Technical — how it's computed](#technical-how-its-computed) Every job — a survey, a set of remedial works, or both together — moves through the same spine : one line that shows exactly where it is, what happens next, and (honestly) how it got there if the tidy path wasn't followed. Tiered — Basics for reading the spine day to day, Deep dive for the "flexibility with caveats" gates and what each chip means, Technical for how it's derived. ## Basics — reading a case's position Open any work order or works order and you'll see the case lifecycle rail — every stage, in order, with each one marked: - ✅ done — reached, with a date where one is recorded. - 🔵 current — where the case is right now. - ⚪ upcoming — not reached yet. - ⊖ skipped — doesn't apply to this case (see survey-only / works-only below) — struck through, never shown as if it happened. The full spine, in order: Raised → Survey Scheduled → Surveyed → Summary Provided → Works Scheduled → Works Complete → Verified → Closed Alongside the rail, the management dashboard always shows one Next step button — the single action that moves the case forward from wherever it currently sits (send the resident summary, schedule a verification re-survey, close the case, and so on). There's no separate place to hunt for "what do I do now" — it's always the same button, in the same place, for every case. The mobile capture app shows the same rail, read-only. A surveyor or field operative sees exactly where their job sits in the process — on the sealed survey record and on the works job detail — but the caveat actions below (marking a summary as sent externally, verifying by attestation, closing a case) are dashboard/coordinator actions only, never available from the field app. The app answers "where is this job", not "what do I decide". ## Deep dive — flexibility with caveats Real housing management doesn't always fit the tidy path — a summary gets posted rather than sent through the platform, a supervisor signs off works on a site visit rather than booking a full re-survey, a photo genuinely can't be taken. Rather than blocking those situations outright (which just pushes them off-system, into a spreadsheet nobody sees) or pretending they didn't happen, every gate below has a primary, evidence-rich path that advances the case automatically, and an explicit, weaker, honestly-labelled alternative that a coordinator can choose instead. The alternative never looks the same as the real thing: it always requires a person, usually a reason, is logged in the audit trail, and shows a visible chip on the record for as long as that record exists. Stage gate Primary path (automatic) Caveat path (manual, always labelled) Summary Provided The written summary is sent to the resident through the platform. Mark summary as provided externally — a coordinator records that it was delivered another way (printed, posted, emailed directly), with an optional note on how. Chip: Summary Provided Externally . Works Complete — photo At least one fingerprinted after-photo is captured. If your organisation's policy makes photos optional for works completion, a completion note is required instead — never a wholly empty record. Chip: Notes Only — No Photo Evidence . Works Complete — location The field app captures a GPS fix at completion. A coordinator completes the job on the operative's behalf from the dashboard (no one was on site to complete it in person) — no location is captured or claimed. Chip: No Presence Data . Verified A follow-up re-survey is raised against the same works order and confirms the hazard is resolved. Verify by attestation — a coordinator records that they inspected and accepted the completed works without a fresh re-survey, with a mandatory reason. Chip: Verified By Attestation — No Re-Survey . Closed Automatically eligible once a case is Verified (or, for a survey that needed no works, once its summary is provided). Close case — a coordinator closes with a reason: Verified , No works needed , or Closed without verification . The last of these always shows amber , never green — it is never dressed up as a verified closure. A few things that are true everywhere on the spine: - Nothing is ever silently substituted. A caveat chip is always visible on the record, in reports, and in the case history — anyone reviewing the file later sees exactly which path was taken. - Statutory clocks are untouched by any of this. Awaab's Law deadlines are computed from their own events and keep running regardless of which path a case took. A caveat can never make a compliance breach look resolved. - Cancelling a job (at any stage, with a reason) is a separate, always-available action — it lands on Closed too, but is tracked distinctly from a genuine closure (see the buckets below). ### Survey-only and works-only cases Not every case runs the full eight stages: - Survey-only. A sealed survey that finds no hazard — or whose summary is enough on its own — skips straight from Summary Provided to Closed (reason: No works needed ). The works stages show as skipped , not upcoming: they were never going to happen for this case. - Works-only. A works order raised directly, with no source survey (for a tenant-reported fix, planned maintenance, or making a property safe), starts at Works Scheduled — the first four stages are structurally skipped, and the record carries its own honest No Source Survey (Direct Works) chip for its whole life, separate from the caveat chips above. - Works raised from a survey, viewed on its own record. A works order's own detail page reports its position from Works Scheduled onward — the earlier stages belong to the survey that raised it, not to the works record itself. ### The buckets, briefly The work orders list groups cases into Not Started / Requires Works / Completed / Closed / Cancelled . Closed means a case concluded and was signed off (via any of the paths in the table above); Cancelled means the job itself was called off. They're kept deliberately distinct — "concluded" and "abandoned" aren't the same story, even though both stop the case from needing further action. ## Technical — how it's computed - The stage is derived, not stored — a pure function ( caseStage() , packages/shared/src/lifecycle.ts ) reads a case's existing fields (status, works state, stage timestamps, and the three caveat markers below) every time it's displayed. There is no separate "current stage" field that can drift out of sync with reality. - The three caveat markers are summaryProvidedExternallyAt/By/Note , attestation ( {by, at, reason} ), and closedAt/By/Reason — each write-once, each set by its own coordinator-only, audit-logged action ( markSummaryProvidedExternally , verifyWorksByAttestation , closeCase ). None of them can be set by a direct client write — every path goes through a server-side callable that checks the caller's role and records the audit event. - For a case where the works happened on a separate works-order record (works raised from a survey), the survey's own stage view cross-references the furthest-progressed, non-cancelled works order linked to it — so the case's position always agrees whichever record you're looking at it from. - The capture app renders the identical caseStage() output through its own read-only presentational component — same facts, same chip vocabulary, redrawn in the app's own visual style. Portal and app can never disagree about a case's position, because both read the same derivation. Next: [Work orders & the Awaab timeline](https://housingsurvey.pro/legal/help/dashboard-workorders/), or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — Evidence | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/dashboard-evidence/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — Evidence # Management Dashboard — Evidence ProSurvey Apps Limited (company no. 17118570) · Help centre The Evidence area is where sealed surveys land. It's your searchable record of every completed inspection, with integrity verification and one-click reports. Tiered — Basics for day-to-day use, Deep dive for verification and versions, Technical for how it's stored. ## Basics — finding and reading a survey - Open Evidence from the sidebar. - The list shows the most recent sealed surveys, newest first, with property, status and date. - Search by address or reference, or filter by status. - Click a survey to open it — you'll see the rooms, readings, photos, assessments (HHSRS, condensation, psychrometrics) and the report narrative. - Click Report to generate a branded, print-ready report; use your browser's print/PDF to save or send it. Large estates: the list loads the most recent records for speed. Use Load older records at the bottom to page back through history. ## Deep dive — integrity & versions - Verify integrity. Each sealed survey can be checked against its hash chain. A verified record confirms it hasn't been altered since sealing; a broken chain is flagged (quarantined) and raises an alert. - Quarantine banner. If a record's integrity check fails, a banner appears — the record's bytes are never changed , only flagged, so the original is preserved for investigation. See the tamper runbook for the response process. - Versions. When an authorised edit is made to a sealed report, a new version is created and chained to the original; every prior version is kept and viewable, so you can see and export the data from any version, not just the latest. (Report versioning is rolling out under the versioning track.) ## Technical — how evidence is stored - Immutable, hash-chained: each finalised survey is sealed with a SHA-256 hash chained to the previous record — tamper-evident and append-only. See [Evidence integrity](https://housingsurvey.pro/legal/technical/evidence-integrity/). - Tenant-scoped: you only ever see your own organisation's evidence; isolation is enforced by server-side security rules, not just the UI. - Photos: hashed at capture with EXIF provenance (timestamp, camera). - Export: organisation and subject-access exports include all versions (rolling out under the governance track) . - Residency: stored in the UK (europe-west2). See [Infrastructure](https://housingsurvey.pro/legal/technical/infrastructure/). Rollout note: report versioning and the full export surface are being delivered under the versioning/governance tracks — the immutable sealing and integrity verification are live today. Next: [Properties & imports](https://housingsurvey.pro/legal/help/dashboard-properties/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — Contractors & Onboarding Source: https://housingsurvey.pro/legal/help/dashboard-contractors/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — Contractors & Onboarding # Management Dashboard — Contractors & Onboarding ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [Basics — add a contractor and send work the same day](#basics-add-a-contractor-and-send-work-the-same-day) - [What the status chips mean](#what-the-status-chips-mean) - [Deep dive — the fork, the three external-firm add paths, and the account lifecycle](#deep-dive-the-fork-the-three-external-firm-add-paths-and-the-account-lifecycle) - [The fork: external firm vs in-house contractor surveyor](#the-fork-external-firm-vs-in-house-contractor-surveyor) - [1. Blind add (name only)](#1-blind-add-name-only) - [2. Invite (email present)](#2-invite-email-present) - [3. Issue sign-in credentials](#3-issue-sign-in-credentials) - [Claiming — how "Unclaimed" becomes "Active"](#claiming-how-unclaimed-becomes-active) - [Limits and housekeeping](#limits-and-housekeeping) - [Technical — the security model](#technical-the-security-model) Contractors is your supply-chain directory: every contractor you work with, their trades, insurance and accreditations, and — since the contractor onboarding rework — one entry point that asks what kind of contractor you're adding, then offers every add path without ever blocking your work. Tiered — Basics for adding a contractor and sending work, Deep dive for the fork, the three external-firm add paths and account lifecycle, Technical for the security model. ## Basics — add a contractor and send work the same day - Open Contractors from the sidebar. - Click + Add contractor . You're asked one question first — is this an external firm (they run their own HousingSurvey Pro organisation, or you set one up for them) or an in-house contractor surveyor (a sub-contractor with no account of their own, who signs in as one of your surveyors)? Pick one and the matching form opens; ← Choose again on any of the resulting forms returns to this question. - For an external firm, type the company name — email and phone are optional — and save. That's it: the contractor appears in your list and work orders can be sent to them immediately . Nothing about their own sign-up ever blocks you dispatching work. - Add full company detail (trades, regions, insurance and accreditation expiry dates — these drive automatic expiry warnings) any time by clicking the entry and editing it, or choose "Add full company details instead" from the external-firm form up front if you prefer. - Import CSV bulk-loads your supply chain from a procurement-system export (a separate toolbar button — it's a bulk path, not part of the fork above). ### What the status chips mean Chip Meaning Active A contractor running their own HousingSurvey Pro account, linked to you. Unclaimed You added them (name only, or with credentials issued) and nobody at the contractor has taken the account over yet. Work orders still send normally. Invited — awaiting validation You added them with an email address; they've been emailed an invite and haven't picked it up yet. Work orders still send normally. Credentials issued — unclaimed You generated a sign-in for them (see below) and they haven't yet claimed the account as their own. Suspended You suspended them — no new work orders can be sent until you reactivate. ## Deep dive — the fork, the three external-firm add paths, and the account lifecycle ### The fork: external firm vs in-house contractor surveyor + Add contractor always asks this question first, rather than presenting several separately-labelled buttons — every destination below is still reachable, just one step further in: - External firm — they use HSP. The contractor runs their own HousingSurvey Pro organisation. They manage their own surveyors, insurance and accreditation records; work you send them is ring-fenced to their own account. This branch leads to the three add paths below. - In-house contractor surveyor — they work for you. For a sub-contractor with no HSP account of their own. You fill in their name, the contractor firm they work for, and (optionally) their own email — this creates a normal surveyor login inside your own organisation (consuming one of your surveyor seats), tagged with the firm label so more than one surveyor can share it. There's no invite, subscription or claim step for them at all: a generated sign-in is shown once for you to hand over, exactly like "Issue sign-in credentials" below, just as the direct next step of this form. Requires member-management permission. ### 1. Blind add (name only) For an external firm with no usable email — or when you just want them on the books now . Type the name, save, done. No email is ever sent. The chip reads Unclaimed until someone at the contractor takes the account over. ### 2. Invite (email present) Exactly the same as blind add, plus an invite email to the address you gave (sent through your organisation's own SMTP if configured under Settings, otherwise the platform sender). The chip reads Invited — awaiting validation , with Resend invite and Revoke invite actions on the card. Revoking the invite does not remove the contractor — they simply drop back to Unclaimed . ### 3. Issue sign-in credentials For the external firm whose "email" is a personal Gmail they never check — or who has none at all. Issue sign-in credentials (reached via "Issue sign-in credentials instead" from the external-firm form) generates a ready-made sign-in you hand to them yourself: - The sign-in email is either their own address (if you enter one) or an internally generated placeholder email . The generated address has no mailbox — nothing is ever emailed to it; you give the contractor the email + password directly (phone, in person, a password-manager share). - The password is generated for you, shown once, and never stored — copy it before closing the panel. Lost it? Regenerate credentials rotates it (the old one stops working immediately). - On their first sign-in — portal or field app — the contractor is required to set their own password before anything else loads. - Revoke credentials disables the sign-in entirely (and is audited), without removing the contractor from your list. ### Claiming — how "Unclaimed" becomes "Active" Every contractor you add this way gets its own separate organisation on the platform — it was never inside yours. When a real person at the contractor engages properly, they claim it: - They sign in (with issued credentials, or by signing up with the invite). - Under Settings → My account they add their own email address and click the verification link we send to it. - On their next sign-in, the account is automatically marked claimed — your chip clears to Active , and from that moment the account is theirs alone: you can no longer revoke or regenerate its credentials. Nothing you or they do during claiming interrupts work orders already in flight. ### Limits and housekeeping - You can hold at most 25 unclaimed contractor shells at a time — a hygiene ceiling, not a business limit (claimed contractors don't count). If you hit it, get one claimed or remove one. - Suspending a contractor (in the edit panel) stops new work orders without touching their data or their account. - Every action here — adding, inviting, issuing, regenerating, revoking, claiming — lands in your organisation's tamper-evident audit log. ## Technical — the security model - Contractors are always separate organisations , linked to yours by a grant record. A contractor you add blind is created as a shell organisation (a server-set lifecycle state of "unclaimed", stamped with your org as creator) — outsiders are never made members of your organisation, so the cross-tenant boundary (they see only their own work, never your stock or other contractors' evidence) holds by construction from day one. - The grant is bound and active at creation for all three add paths, which is what makes work orders sendable immediately — validation was redesigned as a claim rather than a gate . - Landlord-issued accounts carry a flag requiring the contractor to set their own password on first login; both apps block first sign-in on an inline change-password step, and only a server call (after a successful password change) clears it. - The platform-generated sign-in addresses are flagged internally as placeholder addresses on the member record; every email fan-out on the platform either takes an explicit recipient or filters out these placeholder addresses — no system path ever attempts delivery to one of them. - Claiming requires a verified email on the signed-in account (Identity Platform's email-verified status, never client-asserted) that is not a placeholder address; the lifecycle flip happens server-side only. Once claimed, the creating landlord's revoke/regenerate paths are refused — a landlord can never lock an independent business out of its own account. - Contractor surveyor seats belong to the contractor's own organisation (shells start on the free Solo tier, one seat), never to the landlord's licence. Unclaimed shells are excluded from platform revenue metrics. This is distinct from the in-house contractor surveyor fork above, which is deliberately the opposite: no separate organisation is created at all, and the login consumes one of the landlord's own surveyor seats, the same as any of the landlord's own staff. [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Management Dashboard — Billing & Invoices | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/dashboard-billing/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Management Dashboard — Billing & Invoices # Management Dashboard — Billing & Invoices ProSurvey Apps Limited (company no. 17118570) · Help centre The Billing area shows your plan, seats, and the invoices and statements for your organisation. Tiered — Basics for viewing and paying, Deep dive for seats and statements, Technical for how it's controlled. ## Basics — your plan & invoices - Open Billing from the sidebar (org admins). - See your current plan and licensed seats . - View invoices — each with its number, date, amount and status (outstanding / paid). - Download an invoice to share with your finance team. HousingSurvey Pro bills by seat . Your plan and seat count are set as part of your agreement; contact your account manager to change them. ## Deep dive — seats, statements & agreements - Seats: a seat is a licensed user of the platform. Adding members beyond your licensed seats is prevented until seats are increased — this is a billing control, not something an org admin can self-grant. - Invoices: issued against your agreement, with a unique number and a clear status. Paid and outstanding invoices are both retained for your records. - Statements: a running record of charges and payments for reconciliation. - Billing agreement: the commercial terms (plan, rate, billing cadence, payment method — invoice/PO/bank transfer) are recorded against your organisation. ## Technical — how billing is controlled - Server-side only: billing fields — seats, plan, invoice records — are not client-writable . An org admin can view them but cannot change seats or billing terms from the UI; changes go through audited server logic operated by the platform. - Audit: billing and commercial actions are recorded as immutable audit events. - Separation of duties: costing on work orders (your SOR rates) is separate from platform billing — one is your repair pricing, the other is your subscription. Rollout note: invoice PDFs, statements, and accounting-integration exports are being delivered under the commercial-operations track — the core invoice/agreement records are in place today. Next: [Integrations — SSO](https://housingsurvey.pro/legal/help/integrations-sso/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Mobile App — Running a Survey | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/app-survey/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Mobile App — Running a Survey # Mobile App — Running a Survey ProSurvey Apps Limited (company no. 17118570) · Help centre How a surveyor completes a survey on-site, from opening an assigned job to sealing the evidence. Tiered — Basics for the everyday flow, Deep dive for the module detail, Technical for how the data is protected. ## Basics — the survey flow - Open your job. Assigned surveys appear in the inbox with due dates. Tap one to open its survey dashboard — a hub of module cards, each showing its live status. - Be on-site. Where your organisation requires it, capture a GPS fix ; editing is only allowed while you're at the property. - Work through the modules (in any order). Each card opens a full-screen module; a Next button walks you to the following section. - Add photos as you go — they're timestamped and fingerprinted at capture. - Sign off , then finalise . Finalising seals the record — it can no longer be edited, and it syncs back to the management dashboard as evidence. ## Deep dive — the modules The survey dashboard covers everything an HHSRS/damp assessment needs: - Survey details — address (pushed from the job) and the GPS fix. - Rooms — per-room readings (temperature, humidity), damp observations and photos. - External analysis — elevations and outdoor conditions; weather can be auto-filled from your location. - Psychrometrics — derived dew-point/vapour-pressure diagnostics from the room readings. - Condensation risk — interstitial (ISO 13788) construction build-ups. - HHSRS hazards — the 2026 hazard assessment. - EPC , Soil & drainage , Ventilation , Floor plan . - Report narrative — the written report sections (property description, external observations, ventilation, timber, damp, executive summary, and more). Each has: - Smart Build — tap options across categories and the app assembles professional wording for you, with a live preview. - AI Polish — tidies your dictated or typed notes using your organisation's own AI (advisory only; it never enters evidence by itself). - Dictation — speak your notes instead of typing. - Sign-off — recorded with a date-and-time stamp. You can reopen and view any survey read-only at any time. ## Technical — how the evidence is protected - On-site enforcement: if your organisation enables it, a survey can only be started and edited within a GPS radius of the property; leaving the radius locks editing. - Photo provenance: each photo is SHA-256-hashed at capture and carries its EXIF timestamp and camera make/model. - Sealing: finalising computes a SHA-256 hash of the record, chained to the previous one — making the finalised survey tamper-evident and append-only . See [Evidence integrity](https://housingsurvey.pro/legal/technical/evidence-integrity/). - Offline: capture works offline; finalising (sealing) needs a connection, and evidence syncs when you reconnect. - AI: runs on your organisation's own provider key; with no key configured, AI features are simply off. Rollout note: some on-site-enforcement and report-adjustment behaviours (job-pushed address, GPS lock-out, currency/units) are configured by your organisation and are rolling out — check your dashboard settings. Next: [Mobile app — offline & sync](https://housingsurvey.pro/legal/help/app-offline/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Mobile App — Install & Sign In | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/app-signin/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Mobile App — Install & Sign In # Mobile App — Install & Sign In ProSurvey Apps Limited (company no. 17118570) · Help centre Contents - [Basics — signing in](#basics-signing-in) - [Option A — you have an email account](#option-a-you-have-an-email-account) - [Option B — you have a tenant login (no email)](#option-b-you-have-a-tenant-login-no-email) - [Deep dive — working for more than one organisation](#deep-dive-working-for-more-than-one-organisation) - [Technical — for IT managers](#technical-for-it-managers) How a surveyor installs the HousingSurvey Pro mobile app, signs in, and (if they work for more than one organisation) switches between profiles. Written in tiers — Basics to get going, Deep dive for multi-tenant use, Technical for IT. Rollout note: email sign-in is live today. The tenant login (username/code + passcode, no email) and the multi-profile switcher are rolling out — this page documents the intended flow; check your dashboard for current availability. ## Basics — signing in You can be set up in one of two ways. Your organisation will tell you which. ### Option A — you have an email account - Install the app and open it. - Enter your email and password . - Tap Sign in . Your assigned jobs appear in the inbox. ### Option B — you have a tenant login (no email) Some surveyors and contractors are set up with a tenant login instead of an email — created for you by your organisation's admin. - Install the app and open it. - Enter your organisation code , your username/code , and your passcode (all provided by your admin). - Tap Sign in . Forgotten your passcode? Your organisation's admin resets it from the management dashboard — there is no public reset for tenant logins. ## Deep dive — working for more than one organisation If you carry out surveys for several companies or housing associations, you can hold a separate profile for each one and switch between them: - Sign in to your first organisation as above. - From the account menu, choose Add another profile and sign in with the second organisation's details (email, or its tenant code + username + passcode). - Switch profiles any time from the account menu. Each profile is scoped to one organisation . You only ever see the jobs, data and settings of the profile you're currently in — profiles never mix. ## Technical — for IT managers - Identity: authentication is handled by Firebase Auth / Identity Platform. Email and SSO users authenticate directly; tenant (username/code) logins are provisioned by a tenant admin and map to a managed identity behind the scenes, so the same security rules and audit apply to every sign-in type. - SSO: if your organisation uses Microsoft Entra ID, staff can sign in with their corporate identity — see Integrations — SSO . - Multi-tenancy: one person may belong to multiple organisations; each app profile is a distinct tenant session. Email accounts can span tenants as multiple memberships; code-based logins are tenant-scoped. - Device security: the app attests via App Check (App Attest on iOS, Play Integrity on Android). A lost device can be cut off centrally — an admin can remotely revoke a user's sessions from the dashboard. - Offline: after first sign-in the app works offline; captured evidence syncs when connectivity returns. Next: [Mobile capture app — running a survey](https://housingsurvey.pro/legal/help/app-survey/) (in progress) , or back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Mobile App — Offline & Sync | HousingSurvey Pro Source: https://housingsurvey.pro/legal/help/app-offline/ [Legal & compliance](https://housingsurvey.pro/legal/) / [Help centre](https://housingsurvey.pro/legal/help/) / Mobile App — Offline & Sync # Mobile App — Offline & Sync ProSurvey Apps Limited (company no. 17118570) · Help centre Surveyors work in properties with poor or no signal, so the HousingSurvey Pro app is offline-first : the on-site capture a survey needs works without a connection (finalising, AI wording and online lookups still need one), and data syncs when you're back online. Tiered — Basics for how it feels, Deep dive for what happens offline, Technical for how sync and evidence integrity hold up. ## Basics — it just keeps working - Open and complete surveys with no signal — readings, photos, notes, assessments and sign-off all work offline. - Your work is saved on the device as you go; nothing is lost if the app closes or the battery dies. - When a connection returns, completed evidence syncs automatically to the management dashboard. The first time you sign in you need a connection. After that, day-to-day capture works offline. ## Deep dive — what works offline - Capture: rooms, readings, photos (hashed on-device), the report sections, and sign-off. - On-device calculations: psychrometrics, HHSRS scoring, condensation and ventilation checks are computed on the device — no server round-trip. - What needs a connection: first sign-in, pulling newly assigned jobs, some lookups (weather/soil/EPC auto-fill), AI features, and the final sync of sealed evidence. Where a lookup can't run offline, you can enter the values and it's recorded as manually entered. ## Technical — sync & integrity - Local-first storage: drafts are held in the app's local database and survive restarts; syncing is a background reconciliation, not a blocking save. - Sealing offline: a survey can be finalised offline — the SHA-256 hash and chain are computed on-device by the same canonicaliser the server uses, so the record is already tamper-evident before it syncs . On upload the server verifies the same hash (client/server twin parity), so nothing is trusted blindly. See [Evidence integrity](https://housingsurvey.pro/legal/technical/evidence-integrity/). - Conflict-free by design: each survey belongs to one surveyor's device session; sync appends sealed evidence rather than merging concurrent edits. - Photos: captured and fingerprinted locally with EXIF provenance, uploaded when connectivity allows; the hash anchors each image to its record. - Resilience: because field capture doesn't depend on the backend, an outage of the dashboard never stops a surveyor collecting evidence. Back to the [help index](https://housingsurvey.pro/legal/help/). [← Back to help centre](https://housingsurvey.pro/legal/help/) --- ## Data Processing Agreement | HousingSurvey Pro Source: https://housingsurvey.pro/legal/dpa/ [Legal & compliance](https://housingsurvey.pro/legal/) / Data Processing Agreement # Data Processing Agreement Version 2.4 · Effective date: 14 July 2026 · ProSurvey Apps Limited (company no. 17118570), registered in England and Wales. This document is product-accurate and drafted to be thorough, but it is not legal advice . Questions: [contact us](https://housingsurvey.pro/contact/) or email support@prosurvey.app. See also: [Terms of Service](https://housingsurvey.pro/legal/terms/) · [Privacy Policy](https://housingsurvey.pro/legal/privacy/) · [Acceptable Use Policy](https://housingsurvey.pro/legal/aup/) · [Cookie Notice](https://housingsurvey.pro/legal/cookies/) · [Sub-processors](https://housingsurvey.pro/legal/subprocessors/) Contents - [1. Roles and scope](#1-roles-and-scope) - [2. Processing on documented instructions](#2-processing-on-documented-instructions) - [3. Confidentiality](#3-confidentiality) - [4. Security (technical and organisational measures)](#4-security-technical-and-organisational-measures) - [5. Sub-processors](#5-sub-processors) - [6. Data-subject rights](#6-data-subject-rights) - [7. Assistance with obligations](#7-assistance-with-obligations) - [8. Personal-data breaches](#8-personal-data-breaches) - [9. Deletion or return](#9-deletion-or-return) - [10. Audits and information](#10-audits-and-information) - [11. International transfers](#11-international-transfers) - [12. Liability](#12-liability) - [13. Precedence and general](#13-precedence-and-general) - [Annex 1 — Description of processing](#annex-1-description-of-processing) - [Annex 2 — Technical and organisational measures (drawn from the real security posture)](#annex-2-technical-and-organisational-measures-drawn-from-the-real-security-posture) - [Annex 3 — Sub-processors](#annex-3-sub-processors) This Data Processing Agreement forms part of the agreement (the " Agreement ", i.e. the Terms of Service) between ProSurvey Apps Limited (company number 17118570, England and Wales) (" Processor ", " we ", " us ") and the customer organisation (" Controller ", " you ") for the HousingSurvey Pro Service. It governs our processing of Tenant Personal Data and any other personal data we process on your behalf . Where we process personal data as a controller (account, billing, website data), our Privacy Policy applies instead. Terms defined in the Terms of Service have the same meaning here. " UK Data Protection Law " means the UK GDPR, the Data Protection Act 2018, and any successor or related legislation, as amended. ## 1. Roles and scope 1.1 You are the controller and we are the processor in respect of the personal data described in Annex 1 . Where you are yourself a processor for a further controller (for example, a contractor acting for a landlord), you appoint us as your sub-processor and warrant you have authority to do so. 1.2 We process personal data only for the purpose of providing the Service and only as described in this DPA and Annex 1. ## 2. Processing on documented instructions 2.1 We process personal data only on your documented instructions , including those in the Agreement, this DPA, your configuration and use of the Service, and any further written instructions you give — unless required to do otherwise by law (in which case we will inform you, unless legally prohibited). 2.2 We will inform you if, in our opinion, an instruction infringes UK Data Protection Law. We are not obliged to act on an instruction that would. ## 3. Confidentiality We ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations and access personal data only as needed to perform the Service. ## 4. Security (technical and organisational measures) We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, costs, and the nature, scope, context and purposes of processing. Our measures are set out in Annex 2 and are kept under review. We do not currently hold SOC 2, ISO/IEC 27001 or Cyber Essentials certification; we operate to those frameworks and are working towards certification. ## 5. Sub-processors 5.1 You provide general authorisation for us to engage the sub-processors listed in Annex 3 for the processing described. 5.2 We impose data-protection obligations on each sub-processor that are, in substance, no less protective than those in this DPA, and remain responsible to you for each sub-processor's performance. 5.3 We will give you at least 30 days' prior notice of any intended addition or replacement of a sub-processor (by updating the [subprocessors page](https://housingsurvey.pro/legal/subprocessors/) and, where you have subscribed, notifying your organisation administrators), giving you a reasonable opportunity to object on reasonable data-protection grounds . If we cannot resolve a reasonable objection, you may terminate the affected Service as your sole remedy. ## 6. Data-subject rights Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures — including the Service's self-service export and deletion tools — to fulfil your obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). If we receive a request directly, we will not respond to it ourselves (except to direct the individual to you) and will pass it to you promptly. ## 7. Assistance with obligations We assist you, taking into account the nature of processing and the information available to us, with: security of processing (Art. 32); personal-data-breach notification and communication (Arts. 33–34); data-protection impact assessments (Art. 35); and prior consultation (Art. 36). ## 8. Personal-data breaches We notify you without undue delay after becoming aware of a personal-data breach affecting personal data we process for you, and provide the information you reasonably need to meet your own notification obligations. ## 9. Deletion or return On termination of the Service, and at your choice, we delete or return the personal data we process for you and delete existing copies, unless UK Data Protection Law (or another law to which we are subject) requires storage. The Service provides self-service export (for return) throughout the term and for the post-termination export window, and self-service/scheduled deletion , as described in the [Terms of Service](https://housingsurvey.pro/legal/terms/) (clause 10.4) and [Privacy Policy](https://housingsurvey.pro/legal/privacy/) (clause 7). Retention of audit and accounting records, and of tamper-evident evidence for its configured retention period, is as described there. ## 10. Audits and information We make available to you the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. We may satisfy this by providing our security documentation, security-questionnaire responses, and (once obtained) certification/attestation reports, and by reasonable, scoped, confidential audits at reasonable frequency and cost. Our default position is documentation-first (security documentation and questionnaire responses, supplemented by certification/attestation reports once obtained), with a scoped on-site or remote audit step available for cause, on reasonable notice. ## 11. International transfers We process the data plane in the UK (europe-west2, London). Any transfer of personal data outside the UK arising from a sub-processor is made under an appropriate transfer mechanism — that sub-processor's UK IDTA/Addendum to the EU Standard Contractual Clauses (or equivalent), or an applicable adequacy decision, as set out per sub-processor in Annex 3 and on the [subprocessors page](https://housingsurvey.pro/legal/subprocessors/). We will not transfer personal data outside the UK other than as described there without an appropriate safeguard. ## 12. Liability Liability under this DPA is subject to the limitations and exclusions in the Agreement ( [Terms of Service](https://housingsurvey.pro/legal/terms/) , clause 12), except to the extent UK Data Protection Law requires otherwise. ## 13. Precedence and general 13.1 In the event of conflict between this DPA and the rest of the Agreement on a data-protection matter, this DPA prevails. 13.2 This DPA is governed by the law of England and Wales , consistent with the Agreement. ## Annex 1 — Description of processing Item Detail Subject matter Provision of the HousingSurvey Pro damp & mould evidence platform Duration The term of the Agreement, plus the post-termination export/retention windows described in the Terms and Privacy Policy Nature and purpose Capture, storage, hash-chaining, transmission and export of property-condition evidence and related work-management data, on the Controller's behalf Types of personal data Property addresses/UPRNs; environmental readings and observations; photographs of properties; inspection GPS coordinates; surveyor/Authorised-User identifiers; work-order and statutory-deadline data. The Service is designed to describe properties, not people ; the Controller is required not to enter special-category data and to minimise personal data Categories of data subjects Residents/occupiers and other individuals connected to a property (only to the extent the Controller enters such data); the Controller's own staff and contractors (as Authorised Users) Special-category data Not to be processed; the Controller undertakes not to enter it Frequency Continuous, for the duration of the Service ## Annex 2 — Technical and organisational measures (drawn from the real security posture) - UK data residency: Firestore, Cloud Storage, Cloud Functions and authentication pinned to Google Cloud europe-west2 (London) , enforced in code. - Access control: default-deny Firestore/Storage rules; per-organisation isolation; role-based access (owner/org-admin/manager/coordinator/finance/ viewer/surveyor); contractor access only via explicit landlord grants; server-side custom claims minted only by controlled functions; SSO/SCIM on eligible plans. - Authentication: TOTP and phishing-resistant WebAuthn passkeys are available and required by the apps for relevant roles; platform-superadmin rules/callables verify current second-factor proof server-side. Equivalent server-side step-up is not yet universal for ordinary manager/org-admin actions. Passwords are held by Identity Platform; high-entropy API/SCIM bearer tokens are stored only as SHA-256 digests and shown once. - Evidence integrity: server-authoritative finalization (timestamp set by a function, never a device clock); per-property SHA-256 hash chaining with a nightly integrity verifier that flags (never alters) mismatches and raises audit/notification events; append-only, hash-chained audit log per organisation; signed evidence bundles independently verifiable by a third party. - Encryption: TLS in transit; encryption at rest (managed by the cloud platform) throughout. - Application security: app attestation (App Check); upload restrictions (images only, size-capped) enforced by Storage rules; signed webhooks (HMAC-SHA256); rate-limited, audited API access. - Per-tenant AI isolation: survey-content AI runs only on the Controller's own key, scoped strictly to that Controller; no shared platform AI account; refused on finalized records; fails closed when unconfigured. - Logging and monitoring: Cloud logging on functions; append-only audit trail; nightly chain-verification run records. - Backups/continuity: production Firestore has seven-day point-in-time recovery (PITR) plus daily backups retained for 98 days. Evidence Storage has object versioning, 14-day soft delete and a nightly mirror to a separate versioned Archive bucket in London. The same-region backup protects object/ bucket loss while preserving UK residency, but does not cover a whole-London- region outage. See the [compliance mapping](https://housingsurvey.pro/legal/technical/compliance-mapping/) for current recovery-test gaps. These controls are separate from the cryptographic integrity guarantee, which does not depend on backups. This annex reflects our current engineered security posture and is kept under review as controls land. We do not represent an in-progress control as complete, and we add no certification claim until one is actually held. ## Annex 3 — Sub-processors Sub-processor Role Location / residency Google Cloud / Firebase Core hosting, database, storage, auth, functions UK (europe-west2, London) for the data plane Stripe Payments and invoicing UK/EU and US-headquartered; card data is out of our scope entirely (Stripe is PCI-DSS certified). Any transfer outside the UK is under Stripe's standard contractual clauses (or equivalent transfer mechanism) Cloudflare CDN, DNS, WAF, Turnstile bot protection Global CDN network, US-headquartered; any transfer outside the UK is under Cloudflare's standard contractual clauses (or equivalent transfer mechanism) Google Workspace (SMTP) Transactional/notification email US-headquartered (Google LLC) / Ireland (Google Ireland Ltd); any transfer outside the UK is under Google's standard contractual clauses (or equivalent transfer mechanism) Ordnance Survey / Google Places Address lookup (address strings only) Ordnance Survey: UK. Google Places: US-headquartered; any transfer outside the UK is under Google's standard contractual clauses (or equivalent transfer mechanism) EPC register (gov.uk) Public energy-performance lookup UK Google (AI Studio) — public docs assistant only Public website documentation assistant; no Customer/Tenant data US-headquartered; touches only public marketing/documentation content, never personal data Customer-keyed AI providers (Anthropic / Azure OpenAI / OpenAI / Google / BYO endpoint) Advisory survey-content AI — the Controller's own account and DPA Determined by the Controller's arrangement with its chosen provider — this is a sub-processor of the Controller's own choosing, not ours, listed here for transparency The full, current version of this table — kept up to date as sub-processors change — is published on the [subprocessors page](https://housingsurvey.pro/legal/subprocessors/), which this Annex 3 mirrors. ProSurvey Apps Limited · registered in England and Wales, company number 17118570 · HousingSurvey Pro™. ## Changelog - v2.4 (14 July 2026) — Full UK-law B2B SaaS suite drafted (W-E1), published live (W-E2/H-LEGAL-PUBLISH). Supersedes the v1.0 short-form page. --- ## Cookie Notice | HousingSurvey Pro Source: https://housingsurvey.pro/legal/cookies/ [Legal & compliance](https://housingsurvey.pro/legal/) / Cookie Notice # Cookie Notice Version 2.4 · Effective date: 14 July 2026 · ProSurvey Apps Limited (company no. 17118570), registered in England and Wales. This document is product-accurate and drafted to be thorough, but it is not legal advice . Questions: [contact us](https://housingsurvey.pro/contact/) or email support@prosurvey.app. See also: [Terms of Service](https://housingsurvey.pro/legal/terms/) · [Privacy Policy](https://housingsurvey.pro/legal/privacy/) · [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) · [Acceptable Use Policy](https://housingsurvey.pro/legal/aup/) · [Sub-processors](https://housingsurvey.pro/legal/subprocessors/) Contents - [Our approach](#our-approach) - [What we use — strictly necessary (always on)](#what-we-use-strictly-necessary-always-on) - [Consent-based cookies (set only if you accept)](#consent-based-cookies-set-only-if-you-accept) - [Managing cookies](#managing-cookies) - [Changes](#changes) This notice explains the cookies and similar technologies used across HousingSurvey Pro (website, portal and mobile apps), operated by ProSurvey Apps Limited (company number 17118570, England and Wales). It supplements the [Privacy Policy](https://housingsurvey.pro/legal/privacy/) . ## Our approach We keep this minimal . Strictly-necessary cookies are always on and require no action from you. On our marketing website , we also use a cookie-consent banner : analytics and marketing cookies load only if you click Accept , and you can withdraw that consent at any time (see "Managing cookies" below). We do not sell or share data with advertising networks. ## What we use — strictly necessary (always on) Technology Where Purpose Type Authentication / session storage Portal, mobile apps Keep you signed in; maintain your session securely Strictly necessary App Check attestation tokens Portal, mobile apps Confirm requests come from a genuine app instance (anti-abuse) Strictly necessary (security) Cloudflare Turnstile Website forms (contact, sales/support) Distinguish humans from bots without tracking you across sites Strictly necessary (security) Cloudflare edge/security cookies (if set) Website CDN and security integrity Strictly necessary Cookie-consent choice ( hsp_cookie_consent , browser local storage) Website Remembers your Accept/Reject choice so we don't ask again Strictly necessary All of the above are strictly necessary for the Service or website to function securely. Under the Privacy and Electronic Communications Regulations (PECR), strictly-necessary cookies do not require prior consent, but we tell you about them here for transparency. Each item above is deployed for a single, narrow purpose — session security, anti-abuse or CDN/security integrity — which is the basis for its strictly-necessary classification; we do not use any of them for analytics, advertising or profiling. ## Consent-based cookies (set only if you accept) Our marketing website (housingsurvey.pro) shows a cookie-consent banner on first visit. Nothing in this section loads or sets a cookie unless you click Accept. The table below names every technology this site is configured to set on consent — some may not yet be actively collecting data if we have not finished setting them up on our end (see "Status" per row), but none of them ever loads before you accept: Technology Provider Purpose Status Meta Pixel Meta Platforms, Inc. / Meta Platforms Ireland Ltd Advertising and campaign measurement (e.g. understanding which marketing brought a visitor to our site) Set only with your consent LinkedIn Insight Tag LinkedIn Corporation / LinkedIn Ireland Unlimited Company Advertising and campaign measurement (e.g. understanding which marketing brought a visitor to our site) Set only with your consent Firebase Analytics (Google Analytics 4) Google Ireland Limited / Google LLC Understand website usage and improve the website. Also carries a structured technical-error signal (page/script errors, no personal data) as a GA4 event — the nearest equivalent to crash reporting on a website, since a native crash reporter like Firebase Crashlytics has no web equivalent Set only with your consent, when enabled Firebase Performance Monitoring Google Ireland Limited / Google LLC Measure website loading speed and technical performance (page-load, network-request timing) — no content of what you typed or viewed Set only with your consent, when enabled Meta, LinkedIn and Google are all based outside the UK; see the international transfers note in our [Privacy Policy](https://housingsurvey.pro/legal/privacy/) (clause 5) for how that is handled. We will update this table if we enable further providers, with no change to how consent works: they will still load only after you accept, never before. Our portal and mobile apps (signed-in products, not the marketing website) separately use Firebase Analytics (Google Analytics 4) automatically — there is no cookie banner and no opt-in toggle inside a signed-in app, so this is not governed by the consent mechanism above. It collects only anonymised product-usage data (page/screen views, key actions); it never collects your Evidence or organisation data. We rely on legitimate interests (Art. 6(1)(f)) for this automatic, non-cookie product analytics, consistent with clause 10 of the [Privacy Policy](https://housingsurvey.pro/legal/privacy/) . If you would prefer we not process this diagnostic/analytics data about your organisation's use of the portal or app, contact support and we will consider a technical opt-out. Crash and error reporting: our mobile apps use Firebase Crashlytics automatically (no opt-in toggle, same basis as product analytics above) for native crash reports — stack trace, device/OS info, app version; not linked to your account identity. The website and portal/app each also carry a structured technical-error signal (unhandled script errors, no personal data) via the Firebase Analytics channel already described above — website: consent-based; portal/app: automatic. Crashlytics has no web equivalent, so the website's nearest tool is Firebase Performance Monitoring (this section) plus that error signal, not a crash reporter. ## Managing cookies You can withdraw or change your consent choice at any time using "Manage cookies" in the website footer, or the "Manage / withdraw cookie consent" button on this page — either reopens the consent banner so you can pick again. You can also control or delete cookies through your browser settings. Blocking strictly-necessary cookies may prevent parts of the website, portal or app from working (for example, staying signed in, or submitting a protected form). ## Changes We will update this notice if our use of cookies changes, with a new version and date. ProSurvey Apps Limited · registered in England and Wales, company number 17118570 · HousingSurvey Pro™. ## Changelog - v2.4 (14 July 2026) — Full UK-law B2B SaaS suite drafted (W-E1), published live (W-E2/H-LEGAL-PUBLISH). Supersedes the v1.0 short-form page. --- ## Acceptable Use Policy | HousingSurvey Pro Source: https://housingsurvey.pro/legal/aup/ [Legal & compliance](https://housingsurvey.pro/legal/) / Acceptable Use Policy # Acceptable Use Policy Version 2.4 · Effective date: 14 July 2026 · ProSurvey Apps Limited (company no. 17118570), registered in England and Wales. This document is product-accurate and drafted to be thorough, but it is not legal advice . Questions: [contact us](https://housingsurvey.pro/contact/) or email support@prosurvey.app. See also: [Terms of Service](https://housingsurvey.pro/legal/terms/) · [Privacy Policy](https://housingsurvey.pro/legal/privacy/) · [Data Processing Agreement](https://housingsurvey.pro/legal/dpa/) · [Cookie Notice](https://housingsurvey.pro/legal/cookies/) · [Sub-processors](https://housingsurvey.pro/legal/subprocessors/) Contents - [1. Lawful use](#1-lawful-use) - [2. Data-protection and evidence discipline](#2-data-protection-and-evidence-discipline) - [3. Security and integrity](#3-security-and-integrity) - [4. Platform protection and fair use](#4-platform-protection-and-fair-use) - [5. No resale or misrepresentation](#5-no-resale-or-misrepresentation) - [6. AI features](#6-ai-features) - [7. Enforcement](#7-enforcement) This Acceptable Use Policy governs use of the HousingSurvey Pro Service operated by ProSurvey Apps Limited (company number 17118570, England and Wales). It is incorporated into, and forms part of, the [Terms of Service](https://housingsurvey.pro/legal/terms/) . Capitalised terms have the meaning given there. We may suspend or terminate access for breach, as set out in the Terms. You, and everyone you authorise to use the Service (your Authorised Users ), must comply with this policy. ## 1. Lawful use - Use the Service only for lawful purposes and in compliance with all applicable laws, including housing, data-protection, health-and-safety and equality law. - Do not use the Service to store, transmit or process content that is unlawful, infringing, defamatory, harassing, or that violates a third party's rights. ## 2. Data-protection and evidence discipline - Do not enter special-category personal data (for example, health, ethnicity, religious or similar data) into evidence or free-text fields. - Do not enter more personal data than the assessment requires. Records are designed to describe properties, not people . - Ensure you have a lawful basis for any personal data you enter, and that you are authorised to enter it. - Do not knowingly enter false, misleading or fabricated data into an Evidence Record. Evidence integrity depends on honest, competent capture. ## 3. Security and integrity - Do not attempt to circumvent, disable or probe tenancy isolation, security rules, access controls, app attestation, two-factor authentication, or seat/user enforcement. - Do not attempt to alter, delete or forge finalized Evidence Records, audit logs, or hash chains, or to defeat the tamper-evidence mechanisms. - Do not access, or attempt to access, data belonging to another organisation. - Keep your credentials (passwords, passkeys, TOTP, API keys, SCIM tokens, webhook secrets, SSO configuration) confidential; report suspected compromise promptly. ## 4. Platform protection and fair use - Do not scan, penetration-test, load-test, or stress the Service without our prior written authorisation. - Do not use automated means to overload the Service, or exceed documented rate limits. API and SCIM access is rate-limited and audited. - Do not introduce malware, or upload files other than the permitted content types and sizes (uploads are restricted to images within a size cap). - Do not use the free plan, trials or pilots to evade paid limits (for example, by creating multiple organisations to avoid seat/user charges), or share named seats among multiple people to defeat per-seat licensing. ## 5. No resale or misrepresentation - Do not resell, sublicense, or provide the Service to third parties as a service without a written partner agreement. - Do not misrepresent the Service's capabilities — in particular, do not present the Service as a legal/compliance guarantor, or its outputs as statutory determinations or completed statutory reports. The Service is a tool; statutory duties remain yours (see the Terms, clause 2). ## 6. AI features - Treat all AI output as an advisory draft requiring review by a competent person before any use. Do not represent AI output as verified fact or as a professional determination. - Where survey-content AI runs on your own provider key, ensure your use of that provider is lawful and covered by your own agreement with it. ## 7. Enforcement We may investigate suspected breaches and may suspend (immediately, where reasonably necessary — for example, security, unlawful use, or non-payment) or terminate access as set out in the [Terms of Service](https://housingsurvey.pro/legal/terms/) (clause 10). We will tell you where practicable. We may preserve and disclose information where required by law or to protect the Service, our users, or third parties, consistent with our role as processor for Tenant Personal Data described in the [Privacy Policy](https://housingsurvey.pro/legal/privacy/) . ProSurvey Apps Limited · registered in England and Wales, company number 17118570 · HousingSurvey Pro™. ## Changelog - v2.4 (14 July 2026) — Full UK-law B2B SaaS suite drafted (W-E1), published live (W-E2/H-LEGAL-PUBLISH). Supersedes the v1.0 short-form page. --- ## Integrations — Connect Any Housing CMS/HMS | HousingSurvey Pro Source: https://housingsurvey.pro/integrations/ # We don't ask what CMS or HMS you run. Housing associations run decades of history in their housing management system (HMS) or case-management system — we integrate with it rather than replacing it. One canonical, HACT-aligned evidence payload, delivered over whichever channel your IT team prefers. ## REST API Pull HACT-aligned evidence and property data; cursor pagination; scoped API keys; every call audited. OpenAPI definition available. ## Signed webhooks survey.finalized events pushed to your endpoint the moment a record locks — HMAC-SHA256 signed, retried automatically. ## Inbound work orders POST a damp/mould case from your CMS and it appears in a surveyor's app inbox with the statutory clock attached. Evidence links back to your case reference. ## EDI flat-file (CSV) Nightly per-day CSV drops for systems that ingest files rather than webhooks — the way housing IT actually integrates. Ad-hoc date-range exports from the portal. ## SFTP (Platform plan) Connect to your own SFTP server — no API project required. EDI drops, reports, letters, invoices and your tenancy register delivered out; property/UPRN stock, SOR schedules and tenancy records pulled in. Per-server keys, fail-closed host-key pinning. [Learn more →](https://housingsurvey.pro/integrations/sftp/) ## Microsoft Power Automate Import our OpenAPI definition as a custom connector and your team wires evidence into Dynamics, SharePoint, Teams and most housing systems without code. ## Works with your stack Because the channels above are standard, HousingSurvey Pro connects to systems including NEC Housing, Civica Cx, MRI Housing, Aareon QL, Totalmobile, Plentific, Oneserve, Joblogic — and anything else with an API, a file importer, or a Power Platform estate. Named-vendor adapters are built with pilot customers on demand. [Developer docs](https://housingsurvey.pro/api/) --- ## SFTP Integration for Housing Systems | HousingSurvey Pro Source: https://housingsurvey.pro/integrations/sftp/ # SFTP: the file transfer your housing system already knows how to do. Not every housing CMS speaks webhooks, and not every IT team wants to stand up an API project for one integration. SFTP is the plainer alternative housing IT has run for decades: a folder on a server you already control, files landing in it or being picked up from it. HousingSurvey Pro connects to that server as a client — no API project, no inbound firewall rule for us to reach you, nothing new to install beyond one key on an account you already manage. Platform plan SFTP is included on the Platform tier and above, alongside the REST API, webhooks and EDI exports — see [pricing](https://housingsurvey.pro/pricing/). ## You keep the server. That's the security model, not a limitation. HousingSurvey Pro is always the client , never a listener you connect into — there is no shared or multi-tenant SFTP endpoint anywhere in the platform for someone to find. Every server you add gets its own freshly minted keypair (ed25519 by default, RSA-4096 if your server needs it); only the public half is ever shown to you, and the private half never leaves HousingSurvey Pro's backend. The first successful connection's host-key fingerprint has to be explicitly confirmed before it's trusted — after that, the connection fails closed if your server ever presents a different key, whether that's a legitimate re-key or something worse. Revoking access is entirely in your hands: remove the key from your server, or disable the account, and the connection stops working immediately. ## What moves, in which direction Two directions, both built on the same connection and the same delivery guarantees: - Outbound. Nightly EDI flat-file exports can deliver straight to your server alongside the existing download link — SFTP delivery is additional, never a replacement, so a delivery problem never blocks the export itself. Survey report PDFs, works-completed PDFs, resident letters, invoices and your tenancy register can each be sent to a chosen server on demand. Every file lands via a write-then-rename — nothing watching the folder ever sees a half-written file under its real name. - Inbound. Property/UPRN stock, SOR repair-rate schedules, and tenancy records can be pulled in as CSV files from a folder you point at. Every pull previews first — files found, rows to create or update, anything that failed to parse — and writes nothing until you confirm, at which point the files are re-checked against what you just previewed so nothing gets imported blind. ## Stated plainly: what's not there (yet) No certification claims are made about this feature, and neither is anything not actually built: inbound pulls are manual, not scheduled; the SFTP path takes CSV, not XLSX. If any of that changes, this page changes with it. ## Set up in minutes, not a change request An org admin adds a server under Settings → SFTP servers, mints a key (or uses a password, if that's what your server requires), runs a real connection test, and confirms the fingerprint. From there, sending or pulling files is a couple of clicks — no ticket to your integration vendor, no waiting on anAPI allowlist. The [full setup guide](https://housingsurvey.pro/legal/help/integrations-sftp/) walks through every step, including what each test-connection failure actually means. [Start free — no card, no call](https://portal.housingsurvey.pro)[See every integration channel](https://housingsurvey.pro/integrations/)[Try the live demo](https://demo.housingsurvey.pro) ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) --- ## Help Centre — Self-Serve Guides | HousingSurvey Pro Source: https://housingsurvey.pro/help/ # Help centre Everything here is self-serviceable, end to end — you'll never have to talk to us. But you can: [contact us](https://housingsurvey.pro/contact/) (support@prosurvey.app is a real inbox with real humans), and [walkthroughs](https://housingsurvey.pro/demo/) are free. Want more depth on a specific area? See the full [help centre handbook](https://housingsurvey.pro/legal/help/), or the [Trust & Security Handbook](https://housingsurvey.pro/legal/technical/) for IT/procurement detail. [Create your organisation & the setup wizard](#get-started)[Import formats (with sample files)](#imports)[Invite users & manage seats](#users)[Contractors (your supply chain)](#contractors)[Work orders & Awaab's Law timelines](#awaab)[The mobile app (works offline in the field)](#app)[Evidence, verification & bundles](#evidence)[Single sign-on — Microsoft, Okta, Google (Enterprise)](#sso)[SCIM provisioning (Enterprise)](#scim)[AI assistance — your keys, your tenant](#ai)[Connect your case-management system](#integrations)[Viewing & downloading your data](#data)[Billing & plans](#billing)[GDPR — export & deletion, fully self-serve](#gdpr)[Troubleshooting](#faq) ## 1 · Create your organisation & the setup wizard Sign in to the [portal](https://portal.housingsurvey.pro) with email/password, Google, Apple, or your organisation's SSO. First person from your organisation? Choose Create organisation : pick landlord (housing association) or contractor and you're on the free Solo plan instantly — full evidence engine, one surveyor seat, no card. The setup wizard opens automatically and walks you through everything (every step skippable, progress saved — resume from the Dashboard): ① organisation profile & capture policy (require GPS? photo per hazard? quality check?) → ② property import (CSV) → ③ team invites (each person with their own role) → ④ contractors (your supply chain) → ⑤ integrations quick-connect → ⑥ field-app linking (store links + calendar feed). ## 2 · Import formats (with sample files) Every import documents its expected layout inline and validates row-by-row, citing the layout on any error ("row 3: postcode missing"). Columns match by header name in any order; parsers tolerate BOM, CRLF and quoted fields; required fields are strict. Prepare your data before you even sign in: Properties — [properties-example.csv](https://housingsurvey.pro/samples/properties-example.csv): uprn, addressLine1, addressLine2, postcode, localAuthority, tenureType, archetype. The UPRN keys the property's tamper-evident evidence chain; rows without one import flagged for review and match via OS Places at first capture. Team — [team-invites-example.csv](https://housingsurvey.pro/samples/team-invites-example.csv): email, name, role (surveyor / manager / org-admin — mix roles freely, one row per person). Contractors — [contractors-example.csv](https://housingsurvey.pro/samples/contractors-example.csv): company details, trades, regions, insurance and accreditation expiry dates. ## 3 · Invite users & manage seats Portal → Members & seats . Each row is one person with their own role: surveyors capture evidence in the app and use licensed seats; managers dispatch work orders, track compliance and view evidence; org-admins also control billing, integrations and the team. Managers and admins are free on every plan — pricing is per surveyor. Paste a whole list of emails into any row to fan it out, or import the CSV. Seats are platform-enforced: activating a surveyor beyond your licence prompts a self-serve upgrade (prorated by Stripe). Only org-admins can grant the org-admin role, and the platform guarantees at least one org-admin always remains. ## 4 · Contractors (your supply chain) Portal → Contractors : rich records — trading name, Companies House number, contacts, trades, regions, insurance and accreditations (PCA, CHAS, Gas Safe…) with expiry dates that drive automatic warnings : amber six weeks out, red when lapsed, flagged again when you dispatch a work order. + Add contractor asks one question first — an external firm (they run their own HousingSurvey Pro organisation) or an in-house contractor surveyor (they sign in as one of your own surveyors, no account of their own)? For an external firm, name-only takes seconds and work orders send immediately; adding their full company detail instead generates an invite code (e.g. HSP-4F2A9C1B ) their org admin redeems under Integrations → "Join a landlord" to link up formally. Either way, their captured evidence lands in your chains, and they never see your internal notes or rates. ## 5 · Work orders & Awaab's Law timelines Create work orders in the portal (search your property register — the job links to the property and its evidence chain) or push them from your CMS. Set when the hazard was reported and its severity, and the statutory clock computes server-side, in working days : significant hazards → investigate within 10 working days → written summary +3 → works begin +5; emergency hazards → 24 hours . You're alerted in the portal (and by webhook, and in subscribed calendars) before every deadline, and every alert is written to the append-only audit log — if you're ever challenged, you can prove you were warned and when you acted. Completed evidence carries the full timeline in its court-ready bundle. ## 6 · The mobile app (works offline in the field) HousingSurvey Pro is free, with no in-app purchases — [now live on Google Play](https://play.google.com/store/apps/details?id=com.housingsurvey.pro); the App Store listing is on the way (try the field app in your browser right now from the live demo in the meantime, or ask us for an early iOS build). Sign in as in the portal. Surveyors see their dispatched jobs with property details already attached. Capture works completely offline (basements, voids, tower blocks): rooms with readings (dew point derived live), photos SHA-256-fingerprinted at capture, voice dictation on every field , ventilation checks with live Part F assessment, an HHSRS-aware hazard record, a floor-plan sketch with damp/mould pins, and a signature sign-off. Everything syncs when signal returns. Finalize seals the record permanently — server-side, hash-chained to the property, re-verified nightly. No app or API path can edit a finalized record, and any change to a sealed record — however it happened — breaks its cryptographic chain and is detected automatically. Not even we can edit history undetectably. ## 7 · Evidence, verification & bundles Portal → Evidence lists every record with chain status; open one for readings, photos, ventilation, floor plan, sign-off and the record hash. Properties shows each address's full timeline — work orders and sealed evidence in one place, two clicks from any red deadline to the underlying proof. Evidence bundle downloads a signed ZIP: canonical record JSON, chain proof (re-verified at export), statutory timeline, original photos named by capture hash, and a SHA-256 manifest — built for ombudsman and legal use. ## 8 · Single sign-on — Microsoft, Okta, Google (Enterprise) Fully self-serve federation: Portal → Integrations → Single sign-on . Microsoft Entra ID : create an app registration (Web platform, redirect URI https://housingsurvey-pro.firebaseapp.com/__/auth/handler ) and paste its client ID + issuer. Okta or any SAML IdP : upload your metadata.xml . Google Workspace : just register your domain. From then on your users simply enter their work email at sign-in and are routed to your identity provider automatically — no codes, nothing to remember. Email/password remains available for organisations without SSO. ## 9 · SCIM provisioning (Enterprise) Portal → Integrations → SCIM → generate your per-org endpoint + bearer token (shown once). In Entra ID: Enterprise applications → Provisioning → paste both. Joiners arrive as surveyors (seats enforced), deactivations disable access instantly — and deprovisioning never deletes evidence. ## 10 · AI assistance — your keys, your tenant AI is optional, advisory-only , and runs exclusively on your organisation's own API key — Google Gemini, OpenAI, Anthropic, your Azure OpenAI tenant, or any OpenAI-compatible endpoint. Survey data is never sent to a shared or platform-owned AI account, which eliminates cross-tenant exposure. AI suggestions never enter the sealed evidence record, and AI is refused entirely on finalized records. Setup (org-admin, two minutes): Portal → Integrations → AI → pick your provider → the panel deep-links to that provider's key page (Gemini keys are free at [Google AI Studio](https://aistudio.google.com/app/apikey)) → paste the key → Test connection . Models default to Auto — always the latest fast model for your provider; override any time. ## 11 · Connect your case-management system Work orders in, evidence out — REST API, HMAC-signed webhooks, nightly EDI flat files, SCIM, calendar feeds, and a Power Automate connector. Configuration is self-serve under Integrations (Platform plan and above); everything technical — endpoint reference, signature verification code, file layouts, sample files — lives in the [Developers section](https://housingsurvey.pro/developers/). ## 12 · Viewing & downloading your data Evidence bundles per record, EDI CSV exports over any date range, full API access — your data is yours on every plan, including free, including after cancellation. ## 13 · Billing & plans Portal → Billing : Solo (free) / Team £29 / Platform £59 / Enterprise £99 per surveyor per month, annual = two months free. Every tier also includes a free office-user bundle (Solo 2, Team 5, Platform 15, Enterprise unlimited) — office users are owner/org-admin/manager/coordinator/finance roles; extra ones above the bundle are £6/user/month on Team and Platform. Viewers are always free and unlimited on paid plans (capped at 3 on Solo). Card checkout via Stripe with VAT invoices; change seats or plan any time, prorated. Prefer to pay by invoice — PO number, BACS/bank transfer, agreed payment terms — instead of a card? [Talk to us](https://housingsurvey.pro/pricing/#invoicing); Team and Platform can move to annual invoice billing, and Enterprise is invoiced by default with negotiated terms. Cancel any time — you drop to free Solo and keep every record. A feature outside your plan simply doesn't clutter your day-to-day work with a control you can't use; in Settings, a locked section instead shows what it does and the plan it needs, with a one-click link to upgrade — never a greyed-out control pretending to be usable. ## 14 · GDPR — export & deletion, fully self-serve Export everything : org-admins download a complete ZIP of the organisation's data. Delete your account : self-serve, immediate redaction of your personal data (sealed evidence is retained under UK GDPR Art. 17(3) legal-claims grounds, with your identifiers redacted). Delete the organisation : org-admins request it with a typed confirmation; a 90-day window lets you cancel, then everything is purged. No emails to send, no humans to wait for. ## 15 · Troubleshooting "No seats available" — you're activating a surveyor beyond your licence: add seats on Billing, or invite them as a (free) manager. Can't see your organisation after being invited? — sign in with the exact email that was invited, then "Refresh access". App won't sync? — it will queue safely offline indefinitely; check the device has signal and the record list shows the sync badge. Invite code not recognised? — codes are single-use; ask the landlord to check the contractor card for the current one. Anything else: [contact support](https://housingsurvey.pro/contact/) (support@prosurvey.app). --- ## Damp & Mould Compliance Software by Country | HousingSurvey Pro Source: https://housingsurvey.pro/global/ # Damp & mould compliance software, by country. The obligation is the same everywhere social and community housing is regulated: keep homes free of damp and mould, and be able to prove the condition of each home and the action taken. The regime that enforces it differs by jurisdiction. Choose your market: - [EnglandAwaab's Law (Social Housing Regulation Act 2023)](https://housingsurvey.pro/global/damp-and-mould-compliance-software-england/) - [WalesWHQS 2023 / Renting Homes (Wales) Act](https://housingsurvey.pro/global/damp-and-mould-compliance-software-wales/) - [ScotlandSHQS / Awaab's Law (Housing (Scotland) Act 2025)](https://housingsurvey.pro/global/damp-and-mould-compliance-software-scotland/) - [Northern IrelandFitness Standard / Decent Homes NI](https://housingsurvey.pro/global/damp-and-mould-compliance-software-northern-ireland/) - [IrelandHousing (Standards for Rented Houses) Regulations](https://housingsurvey.pro/global/damp-and-mould-compliance-software-ireland/) - [AustraliaCommunity housing / NRSCH](https://housingsurvey.pro/global/damp-and-mould-compliance-software-australia/) - [New ZealandHealthy Homes Standards](https://housingsurvey.pro/global/damp-and-mould-compliance-software-new-zealand/) - [CanadaSocial housing providers](https://housingsurvey.pro/global/damp-and-mould-compliance-software-canada/) - [United StatesPublic housing authorities / HUD NSPIRE](https://housingsurvey.pro/global/damp-and-mould-compliance-software-usa/) This page is general information, not legal advice. Compliance regimes differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in Wales Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-wales/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / Wales # Damp & mould compliance software in Wales. In Wales, the Welsh Housing Quality Standard 2023 and the Renting Homes (Wales) Act frame a social landlord's duty to keep homes free of serious hazards — which turns on being able to evidence the condition of each home over time. ## The applicable regime Welsh Housing Quality Standard 2023 and the Renting Homes (Wales) Act 2016. ## What HousingSurvey Pro provides Contemporaneous, geo-stamped evidence per property, portable into your existing housing systems. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in Wales? Welsh Housing Quality Standard 2023 and the Renting Homes (Wales) Act 2016. In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in Wales? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. Contemporaneous, geo-stamped evidence per property, portable into your existing housing systems. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in United States Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-usa/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / United States # Damp & mould compliance software in United States. In the United States, public housing authorities are inspected under HUD's NSPIRE standard, which explicitly assesses moisture and mould — making a dated, defensible evidence trail essential. ## The applicable regime HUD NSPIRE inspection standard (moisture and mould among assessed conditions). ## What HousingSurvey Pro provides NSPIRE-ready condition evidence, geo-stamped and tamper-evident, across a PHA's stock. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in United States? HUD NSPIRE inspection standard (moisture and mould among assessed conditions). In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in United States? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. NSPIRE-ready condition evidence, geo-stamped and tamper-evident, across a PHA's stock. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in Scotland Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-scotland/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / Scotland # Damp & mould compliance software in Scotland. In Scotland, the Scottish Housing Quality Standard and the incoming Awaab's Law provisions under the Housing (Scotland) Act 2025 push social landlords toward dated, defensible damp and mould records. ## The applicable regime Scottish Housing Quality Standard and Awaab's Law provisions under the Housing (Scotland) Act 2025. ## What HousingSurvey Pro provides Statutory-clock tracking and tamper-evident evidence built for Scottish social landlords and their contractors. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in Scotland? Scottish Housing Quality Standard and Awaab's Law provisions under the Housing (Scotland) Act 2025. In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in Scotland? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. Statutory-clock tracking and tamper-evident evidence built for Scottish social landlords and their contractors. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in Northern Ireland Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-northern-ireland/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / Northern Ireland # Damp & mould compliance software in Northern Ireland. In Northern Ireland, the statutory Fitness Standard and Decent Homes-style expectations require social landlords to identify and remedy serious hazards — and to show they did so. ## The applicable regime The statutory Fitness Standard and Decent Homes NI expectations. ## What HousingSurvey Pro provides Defensible, contemporaneous evidence across your stock, whoever carries out the inspection. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in Northern Ireland? The statutory Fitness Standard and Decent Homes NI expectations. In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in Northern Ireland? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. Defensible, contemporaneous evidence across your stock, whoever carries out the inspection. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in New Zealand Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-new-zealand/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / New Zealand # Damp & mould compliance software in New Zealand. In New Zealand, the Healthy Homes Standards set specific requirements for moisture ingress, drainage and ventilation in rental homes — all of which need to be evidenced. ## The applicable regime Healthy Homes Standards (moisture ingress, drainage, ventilation). ## What HousingSurvey Pro provides Structured, dated moisture and ventilation evidence per property, ready for compliance review. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in New Zealand? Healthy Homes Standards (moisture ingress, drainage, ventilation). In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in New Zealand? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. Structured, dated moisture and ventilation evidence per property, ready for compliance review. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in Ireland Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-ireland/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / Ireland # Damp & mould compliance software in Ireland. In Ireland, the Housing (Standards for Rented Houses) Regulations set minimum standards including freedom from damp and mould — enforced by local authority inspection, where a dated evidence trail matters. ## The applicable regime Housing (Standards for Rented Houses) Regulations. ## What HousingSurvey Pro provides Geo-stamped, tamper-evident records that stand up to local-authority inspection. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in Ireland? Housing (Standards for Rented Houses) Regulations. In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in Ireland? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. Geo-stamped, tamper-evident records that stand up to local-authority inspection. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in England Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-england/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / England # Damp & mould compliance software in England. In England, Awaab's Law sets fixed statutory timescales for social landlords to investigate and remediate damp and mould — and the standard of proof is a contemporaneous, tamper-evident record. ## The applicable regime Awaab's Law (Social Housing (Regulation) Act 2023), in force for the social rented sector from 27 October 2025, with the reformed HHSRS (2026) underneath it. ## What HousingSurvey Pro provides Stock-wide statutory clocks, hash-chained evidence and case-management integration for associations and councils. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in England? Awaab's Law (Social Housing (Regulation) Act 2023), in force for the social rented sector from 27 October 2025, with the reformed HHSRS (2026) underneath it. In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in England? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. Stock-wide statutory clocks, hash-chained evidence and case-management integration for associations and councils. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in Canada Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-canada/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / Canada # Damp & mould compliance software in Canada. In Canada, social and community housing providers operate under provincial standards that require homes to be maintained free of health hazards including damp and mould, with inspection records to prove it. ## The applicable regime Provincial social-housing maintenance and habitability standards. ## What HousingSurvey Pro provides Contemporaneous, tamper-evident inspection evidence across a provider's portfolio. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in Canada? Provincial social-housing maintenance and habitability standards. In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in Canada? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. Contemporaneous, tamper-evident inspection evidence across a provider's portfolio. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Damp & Mould Compliance Software in Australia Source: https://housingsurvey.pro/global/damp-and-mould-compliance-software-australia/ [Home](https://housingsurvey.pro/) / [Global](https://housingsurvey.pro/global/) / Australia # Damp & mould compliance software in Australia. In Australia, community housing providers registered under the National Regulatory System for Community Housing (NRSCH) must maintain properties to a defined standard — including managing damp and mould with a clear record. ## The applicable regime National Regulatory System for Community Housing (NRSCH) performance standards. ## What HousingSurvey Pro provides Portfolio-wide condition evidence for community housing providers and their maintenance contractors. - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Tamper-evident — hash-chained per property so any later change is detectable. - Portable — flows into your existing housing systems by API, webhook or EDI. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## Frequently asked questions ### What compliance regime applies to damp and mould in Australia? National Regulatory System for Community Housing (NRSCH) performance standards. In every case the provider needs a dated, contemporaneous record of the condition of each home and the action taken. ### Does HousingSurvey Pro work for providers in Australia? Yes. HousingSurvey Pro captures geo-stamped, tamper-evident damp and mould evidence and integrates with your existing housing systems by API, webhook or EDI. Portfolio-wide condition evidence for community housing providers and their maintenance contractors. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Compliance regimes and standards differ by jurisdiction and change over time — always confirm the current requirements that apply to your organisation. --- ## Features — Hash-Chained Damp & Mould Evidence | HousingSurvey Pro Source: https://housingsurvey.pro/features/ # The record is the product. HousingSurvey Pro's deliverable is the record, not a report. Branded PDF renderings — survey evidence reports, works-completed packs, resident letters — are generated on demand from the sealed, hash-chained record whenever you need one; the record itself is what flows into your housing management system (HMS) or case-management system by API, webhook, EDI or SFTP. A PDF is a rendering of that evidence, never a replacement for it. ## Indestructible contemporaneous records Server-authoritative finalize The completion timestamp is set by our servers, never a device clock — no backdating, accidental or otherwise. Lock-on-Complete Once finalized, a record cannot be edited or deleted by anyone — surveyor, manager, admin, or us. Corrections create superseding versions; the original survives. Hash-chained per property Every finalized record embeds the SHA-256 fingerprint of the previous record for the same UPRN, building an unbroken evidence timeline per home. A nightly verifier recomputes every chain and records its clean runs. Append-only audit log Every create, edit, finalize, export and API read is logged in a hash-chained, client-unwritable audit trail. ## Built for the field Offline-first capture Basements, voids, tower-block cores — the app works with no signal and syncs when connectivity returns. Geo-stamped A GPS fix (with accuracy radius) is captured on site and sealed inside the hashed record. Photo provenance Every photo is fingerprinted (SHA-256) at the moment of capture; the fingerprint travels inside the record and names the stored file. Survey science built in Dew point derived live from temperature and RH; condensation-risk warnings at capture time — the same engine trusted by DampApp Pro surveyors. ## Built for organisations Landlords and contractors Contractor organisations work under scoped grants. Their surveyors capture against your stock; the evidence chain belongs to you. Work orders Cases flow from your CMS (or the portal) to a surveyor's inbox with the Awaab's Law clock attached, and evidence flows back automatically on completion. Entra ID single sign-on OIDC or SAML per organisation — joiners and leavers follow your own identity provider. UK data residency Everything lives in the London cloud region — enforced in code, not policy. Signed evidence bundles One click exports a ZIP: the record, its canonical form, the chain proof (verified at export), original photos named by fingerprint, and a manifest of every file's hash. Built for ombudsman and legal use. SFTP delivery & import Send EDI drops, reports, letters, invoices and your tenancy register — and pull property/UPRN, SOR and tenancy data back in — over SFTP to a server you control. Per-server keys, fail-closed host-key pinning. Resident letters, every case stage Generate a branded PDF letter at survey-scheduled, works-scheduled, works-completed, case-closed and other case moments — always freely editable, with an optional AI-drafted starting point where it's genuinely useful. Email, print or view; the "From" sign-off defaults to whoever's sending it. On-brand PDF theming Your logo and brand colour are on every generated PDF by default; Team plan and above additionally unlocks a dedicated theme colour, font choice and cover layout. Works-completed packs group after-photos by room and show the completion visit's own GPS fix and timestamp. Tenancy register Who lives where, alongside your property stock: tenant contacts and occupancy status, CSV import/export, and (Platform plan) delivery over the same SFTP connection as everything else. [Start free — no card, no call](https://portal.housingsurvey.pro)[See integrations](https://housingsurvey.pro/integrations/) ## Questions a buyer actually asks ### Does HousingSurvey Pro generate PDF reports? Yes — branded, org-themable PDF renderings (survey evidence reports, works-completed packs, resident letters at every case stage) are generated on demand from the sealed record. The hash-chained record itself remains the authoritative deliverable, flowing into your case-management system by API, webhook, EDI or SFTP; a PDF is a rendering of that evidence, never a replacement for it. ### Does the app work without signal in the field? Yes. Capture is offline-first: basements, voids and tower-block cores with no signal still let a surveyor complete a full record, which syncs automatically the moment connectivity returns. ### Can contractors use the same system as the landlord? Yes. Contractor organisations work under scoped grants issued by the landlord: their surveyors capture evidence against the landlord's properties, and the finalized records belong to the landlord's own evidence chain, not a separate contractor silo. ### What identity provider does HousingSurvey Pro support? Microsoft Entra ID via OIDC or SAML, configured per organisation, with SCIM for automatic joiner/leaver provisioning — your directory stays the source of truth for who has access. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/damp-survey-app) --- ## Frequently Asked Questions | HousingSurvey Pro Source: https://housingsurvey.pro/faq/ # Frequently asked questions Every question we answer across the site, in one place — the product, features, pricing, security, Awaab's Law compliance and agent/API access. Each section links to the page where the answer lives in context. [The product](#product)[Features & the field app](#features)[Pricing, seats & billing](#pricing)[Security & data](#security)[Awaab's Law — the basics](#awaabs-law)[Awaab's Law — the statutory timeline](#timeline)[Awaab's Law — deadlines for damp & mould](#deadlines)[Awaab's Law — for housing associations](#housing-associations)[Awaab's Law — for repairs contractors](#contractors)[The cost of getting evidence wrong](#cost)[Awaab's Law — the written summary](#written-summary)[HHSRS damp & mould hazard scoring](#hhsrs)[AI agents, MCP & API access](#agents)[Compared to AwaabSafe](#vs-awaabsafe)[Compared to PocketSurvey](#vs-pocketsurvey)[Compared to paper & spreadsheets](#vs-paper) ## The product [Homepage →](https://housingsurvey.pro/) What makes HousingSurvey Pro records defensible under Awaab's Law? + Every finalized record is locked server-side with an authoritative timestamp, hash-chained to the previous record for the same property (UPRN), geo-stamped, and covered by an append-only audit log. No app or API path can alter or delete finalized evidence, and any out-of-band change — even at the infrastructure level — breaks the cryptographic chain and is detectable by our verifier. Not even we can edit history undetectably. Does it integrate with our housing management system (HMS) or case-management system? + Yes. HousingSurvey Pro is CMS/HMS-agnostic: a HACT-aligned REST API, signed webhooks, SFTP flat-file EDI, scheduled CSV exports and a Microsoft Power Automate connector mean it connects to NEC, Civica, MRI, Aareon and virtually any other system your IT team runs. Can our contractors use it too? + Yes. Contractor organisations work under scoped grants from the landlord: their surveyors capture evidence against your properties, and the finalized records belong to your evidence chain. How is it priced? + Per surveyor, per month, billed to the organisation — no per-report fees and no app-store purchases. See the pricing page for tiers. ## Features & the field app [Features →](https://housingsurvey.pro/features/) Does HousingSurvey Pro generate PDF reports? + Yes — branded, org-themable PDF renderings (survey evidence reports, works-completed packs, resident letters at every case stage) are generated on demand from the sealed record. The hash-chained record itself remains the authoritative deliverable, flowing into your case-management system by API, webhook, EDI or SFTP; a PDF is a rendering of that evidence, never a replacement for it. Does the app work without signal in the field? + Yes. Capture is offline-first: basements, voids and tower-block cores with no signal still let a surveyor complete a full record, which syncs automatically the moment connectivity returns. Can contractors use the same system as the landlord? + Yes. Contractor organisations work under scoped grants issued by the landlord: their surveyors capture evidence against the landlord's properties, and the finalized records belong to the landlord's own evidence chain, not a separate contractor silo. What identity provider does HousingSurvey Pro support? + Microsoft Entra ID via OIDC or SAML, configured per organisation, with SCIM for automatic joiner/leaver provisioning — your directory stays the source of truth for who has access. ## Pricing, seats & billing [Pricing →](https://housingsurvey.pro/pricing/) Do I need to talk to sales? + No. Create your organisation free in the portal, invite users, connect your systems and upgrade with a card — entirely self-serve on Team and Platform. Enterprise and invoice billing involve a short conversation because terms are negotiated; contact us any time you want one. What counts as a surveyor seat? + Only active surveyors — people capturing evidence in the field app — consume surveyor seats. What is an office user? + Owner, org-admin, manager, coordinator and finance roles are office users — the people running compliance, work orders and billing rather than capturing evidence. Each tier includes a bundle free (Solo 2, Team 5, Platform 15, Enterprise unlimited); extra office users above the bundle are £6/user/month on Team and Platform. Is the viewer role free? + Yes — always, on every paid tier, unlimited. Viewers get read-only access to evidence and dashboards with no create/edit/export rights, so spreading visibility to stakeholders costs nothing. Solo is capped at 3 viewers. Is annual billing cheaper? + Yes — annual is 10× the monthly price, so two months free, whether paid by card or invoice. Can we pay by invoice instead of card? + Yes. Team and Platform can move to annual invoice billing (PO number, BACS/bank transfer, agreed payment terms) — contact us and we'll set it up; card self-serve remains available throughout. Enterprise is invoiced by default with negotiated terms. What happens if we cancel? + You drop to the free Solo plan automatically. Every record, photo and audit trail stays intact and exportable — evidence is never held hostage. Is the mobile app really free? + Yes. The iOS and Android apps are free to install with no in-app purchases; access is granted by your organisation and billed per surveyor seat on the web. Do I need a paid plan to use SFTP? + Yes — SFTP is a Platform-tier feature, alongside the REST API, webhooks and EDI exports it's typically paired with. That covers connecting your own SFTP server, sending reports/letters/invoices to it, pulling in property/UPRN, SOR or tenancy data, and automatic nightly EDI-to-SFTP delivery. Can we put our own branding on generated PDFs? + Every plan, including free Solo, puts your logo and brand colour on survey reports, works-completed packs and resident letters. Team and above additionally unlock full PDF theming — a dedicated theme colour, choice of font and cover layout — across all three document types. ## Security & data [Security →](https://housingsurvey.pro/security/) Can HousingSurvey Pro data leave the UK? + No. Firestore, Storage, Cloud Functions and Authentication are all pinned to the Google Cloud London region (europe-west2) in the codebase itself, not by policy — there is no configuration path that stores or processes tenant data outside the UK. Can a finalized (sealed) record be edited or deleted? + Not through any client or API path, by any role, including our own staff accounts — enforced by database security rules and covered by an automated test suite. Every sealed record is also hash-chained to the one before it for its property: any change made after sealing, by any means including direct database access, breaks the chain and is detected by our nightly verifier. Not even we can edit history undetectably. Corrections create superseding records; originals survive. How is evidence tampering detected? + Each finalized record embeds the SHA-256 hash of its canonical content, chained to the previous record for the same UPRN (property reference). A nightly verifier recomputes every chain end to end and records its clean runs, so the absence of tampering is provable, not merely assumed. Is HousingSurvey Pro Cyber Essentials or ISO 27001 certified? + The platform is designed against Cyber Essentials and ISO/IEC 27001 controls from the first commit; formal certification is on the roadmap and not yet held. We do not claim certification we don't have — contact us for our current security design notes and DPA. How are API keys and webhook secrets protected? + API keys, SCIM tokens and webhook signing secrets are shown once at creation and stored only as SHA-256 hashes thereafter — we cannot retrieve them either. Webhook payloads are HMAC-signed so receivers can verify authenticity. ## Awaab's Law — the basics [Awaab's Law overview →](https://housingsurvey.pro/awaabs-law/) What does Awaab's Law require of social landlords? + Under the Social Housing (Regulation) Act 2023, social landlords in England must investigate reported damp and mould hazards and begin repairs within fixed timescales, with emergency hazards acted on fastest. Scotland has legislated its own version. The exact timescales are being phased in — but the direction is fixed deadlines with evidence of compliance. Why do contemporaneous records matter under Awaab's Law? + When a case reaches the Housing Ombudsman or court, the landlord's defence is its record: when the report arrived, when it was inspected, what was found, what was done. Records assembled after the fact carry little weight; records created at the moment of inspection, provably unaltered since, carry a great deal. How does HousingSurvey Pro prove a record hasn't been altered? + Finalized records are locked server-side with a server-set timestamp, cryptographically chained to the previous record for the same property, and covered by an append-only audit log. A verification sweep recomputes every chain nightly. Exported evidence bundles include the chain proof. ## Awaab's Law — the statutory timeline [Statutory timeline →](https://housingsurvey.pro/awaabs-law/timeline/) When did Awaab's Law come into force? + The Awaab's Law timescales came into force for the social rented sector in England on 27 October 2025, initially covering emergency hazards and damp and mould. Further HHSRS hazard categories are phased in during 2026, with the remaining hazards (except overcrowding) following in 2027. The framework is confirmed to extend to the private rented sector through the Renters' Rights Act. Are the timescales counted in calendar days or working days? + The investigation and repair windows are counted in working days, while the emergency make-safe obligation is counted in hours. Because the exact windows are being phased in by hazard type, always confirm the current statutory figures that apply to the specific hazard and tenure before relying on them. What are the stages of the Awaab's Law timeline? + In broad terms: (1) investigate the reported hazard within the statutory window; (2) provide the tenant with a written summary of the findings; (3) begin repairs within a further set period; and, running in parallel, (4) make safe any emergency hazard within 24 hours. Each stage needs a dated, contemporaneous record to be demonstrable. ## Awaab's Law — deadlines for damp & mould [Deadline calculator →](https://housingsurvey.pro/awaabs-law/deadline-calculator/) What are the Awaab's Law timescales for damp and mould? + From 27 October 2025, social landlords in England must investigate a significant damp and mould hazard within 10 working days of becoming aware, provide a written summary of findings within 3 working days of the investigation ending, and make the property safe within 5 working days of the investigation. Emergency hazards must be made safe within 24 hours. What counts as an emergency hazard under Awaab's Law? + An emergency hazard is one that presents an imminent and significant risk of harm — for example a serious leak, electrical danger, gas safety issue or risk of collapse. These must be investigated and made safe as soon as reasonably practicable and within 24 hours. Does Awaab's Law apply to private landlords? + The 27 October 2025 timescales apply to the social rented sector in England. The government has confirmed the Renters' Rights Act will extend Awaab's Law to the private rented sector, with further hazards phased in during 2026 and 2027. ## Awaab's Law — for housing associations [For housing associations →](https://housingsurvey.pro/awaabs-law/for-housing-associations/) What does Awaab's Law require a housing association to do? + For the social rented sector in England, Awaab's Law requires you to investigate a reported damp and mould hazard within a fixed period, give the tenant a written summary of the findings, and begin repairs within a further set period — with emergency hazards made safe within 24 hours. The duties came into force on 27 October 2025 for emergency hazards and damp and mould, with further HHSRS hazards phased in through 2026 and 2027. The clock and the evidence are both your responsibility to demonstrate. Why isn't our case-management system enough on its own? + A CMS records what your staff typed and when they saved it — which is editable after the fact and carries little evidential weight at the Housing Ombudsman. What defends the association is the contemporaneous field record: captured on site at the time, geo-stamped to the property, and provably unaltered since. HousingSurvey Pro produces that record and then feeds it into your CMS, so you keep your system of record and gain a defensible system of evidence. Can our repairs contractors capture evidence against our stock? + Yes. Contractor organisations work under scoped grants from the landlord: their operatives capture evidence against your properties (by UPRN), and every finalized record belongs to your evidence chain, not theirs. You see the whole stock in one portal regardless of who did the inspection. How does it prove a record hasn't been altered? + Finalized records are locked server-side with an authoritative timestamp, hash-chained to the previous record for the same property, and covered by an append-only audit log. A verification sweep recomputes every chain nightly, and exported evidence bundles carry the chain proof — so neither a contractor, nor a member of staff, nor even we can alter history undetectably. ## Awaab's Law — for repairs contractors [For contractors →](https://housingsurvey.pro/awaabs-law/for-contractors/) We're a repairs contractor, not the landlord — does Awaab's Law affect us? + The statutory duty sits with the landlord, but in practice the evidence is created by whoever attends the property — and that's usually you. If your inspection records aren't contemporaneous and defensible, the association can't demonstrate compliance, which puts your contract and your reputation at risk. Increasingly, associations require their contractors to capture evidence to a defined standard. How does a contractor work inside a landlord's evidence chain? + Your organisation is granted scoped access to the landlord's properties. Your operatives capture geo-stamped, tamper-evident records against those properties by UPRN, and each finalized record becomes part of the landlord's chain — visible to them in their portal in real time. You demonstrate the work was done, on time, to standard, without emailing photos around. Do we need a separate subscription per landlord we work for? + No. Your surveyors capture against whichever landlord has granted your organisation access; the evidence lands in the relevant landlord's chain automatically. It's the same field app and the same workflow whether you're on one association's stock or several. What does this give us that the landlord's portal doesn't? + A contractor-side record that you attended, when, and what you found and did — provably unaltered — so that if a case is scrutinised later, your position is defensible independently of the landlord's system. It's the difference between 'we say we fixed it' and 'here is the contemporaneous, tamper-evident proof'. ## The cost of getting evidence wrong [Cost of getting it wrong →](https://housingsurvey.pro/awaabs-law/roi/) What does it actually cost to get Awaab's Law evidence wrong? + The costs stack up in layers: Housing Ombudsman findings and compensation orders; disrepair claims and legal fees where records can't be produced; re-inspection and repeat visits when the original evidence is incomplete; regulatory scrutiny from the Regulator of Social Housing; and the reputational cost of a case that could have been defended with a contemporaneous record. None of these require the association to have done the wrong thing — only to be unable to prove it did the right thing. How is HousingSurvey Pro priced? + Per surveyor, per month, billed to the organisation — no per-report fees and no app-store purchases. PO numbers, BACS/bank transfer and payment terms are a normal part of how we work with housing associations and councils. See the pricing page for tiers. Where do the savings come from? + Mainly from avoided repeat visits and re-inspections, faster case handling because evidence is complete first time, reduced disrepair exposure because records are defensible, and staff time saved by not retyping field notes into the CMS. We don't publish a fabricated ROI figure — the honest calculation depends on your stock size, claim history and current process, and the pricing/case-handling inputs are all transparent. ## Awaab's Law — the written summary [Written summary requirements →](https://housingsurvey.pro/awaabs-law/written-summary/) How long do we have to issue the written summary? + Within 3 working days of the investigation ending — day 13 overall for a significant damp and mould hazard, counting from the 10 working days allowed to investigate. The clock runs on working days, so weekends and bank holidays don't count. Do we still have to issue a written summary if we find no hazard? + Yes. Awaab's Law guidance is explicit that the tenant must receive a written summary even when the investigation finds no significant hazard — it must explain why no further action is being taken, not just confirm that action is happening. Does the written summary have to be a formal letter? + GOV.UK guidance does not mandate a specific format, but it must be written, given to the tenant (not just logged internally), and dated so the 3-working-day clock is evidenced. Most landlords issue it as a letter or portal message referencing the case. ## HHSRS damp & mould hazard scoring [HHSRS damp & mould scoring →](https://housingsurvey.pro/awaabs-law/hhsrs-damp-and-mould/) What HHSRS category is damp and mould? + Damp and mould growth is its own hazard profile under HHSRS. A hazard scores Category 1 (mandatory local-authority enforcement) at 1,000 points or above; below that it's Category 2 (moderate or low risk, discretionary enforcement). The score comes from the likelihood of harm over the next 12 months combined with the severity of the harm outcome, assessed against the most vulnerable plausible occupant age group, not just the actual tenant. Is a Category 1 HHSRS damp and mould hazard the same as an Awaab's Law emergency? + Not automatically. Awaab's Law's 24-hour emergency track is for hazards presenting an imminent and significant risk of harm — a smaller, more urgent set than every Category 1 finding. A Category 1 damp and mould hazard that isn't imminent typically follows the standard 10/3/5-working-day track, not the 24-hour one. Who decides the HHSRS score — the software or the surveyor? + The surveyor. HHSRS scoring is a professional judgement against a published methodology (likelihood and harm-outcome bands); software can structure the assessment and apply the published formula consistently, but the on-site judgement calls remain the surveyor's. ## AI agents, MCP & API access [For AI agents →](https://housingsurvey.pro/agents/) How does an agent authenticate to the HousingSurvey Pro MCP server? + With an organisation API key as a bearer token (Authorization: Bearer hsp_live_…), minted by an org-admin in the management portal under Integrations → API keys and scoped to exactly what the integration needs. The MCP tools enforce the same scopes as REST API v1, and every call is written to the organisation's append-only audit log. Full detail: https://housingsurvey.pro/auth.md What can the MCP server do? + Read work orders and their statutory-clock timestamps, list finalized evidence, verify a record's tamper-evident hash, and raise or assign work orders — all scoped. It is a read-and-safely-act server, not a bulk-export firehose. Where are the machine-readable descriptors? + MCP server card at /.well-known/mcp/server-card.json (also mirrored at /.well-known/mcp.json), Agent Skills index at /.well-known/agent-skills/index.json, OAuth Protected Resource metadata at /.well-known/oauth-protected-resource, API Catalog at /.well-known/api-catalog, and the OpenAPI 3.0 spec at https://api.housingsurvey.pro/openapi.yaml. Can an agent buy or upgrade a plan directly? + No. Neither REST API v1 nor the MCP server has a billing route or tool — access is read-and-safely-act against an already-provisioned organisation only. Buying, upgrading and seat changes are Stripe-hosted checkout actions a human completes in the management portal. Full detail, including why agentic-commerce discovery protocols like x402, MPP, UCP, ACP and AP2 aren't published on this domain, is at https://housingsurvey.pro/payments.md. ## Compared to AwaabSafe [vs AwaabSafe →](https://housingsurvey.pro/vs/awaabsafe/) Is AwaabSafe the same kind of product as HousingSurvey Pro? + Not quite. AwaabSafe is a deadline-tracking and tenant-reporting layer — a QR code for tenants to report a hazard, and automated statutory-deadline calculation and alerts. HousingSurvey Pro is a field evidence-capture app plus management portal: surveyors record geo-stamped, tamper-evident, hash-chained evidence on site, which flows into your case-management system by API, webhook, EDI or SFTP. The two products solve adjacent but different problems. Does AwaabSafe publish its pricing? + Not on its public site as of this review — pricing isn't listed, so we can't compare it here. HousingSurvey Pro's pricing is public: free to start, then £29-£99 per surveyor per month depending on tier. Check AwaabSafe directly for current pricing. ## Compared to PocketSurvey [vs PocketSurvey →](https://housingsurvey.pro/vs/pocketsurvey/) How much does PocketSurvey cost compared to HousingSurvey Pro? + PocketSurvey's own pricing page lists its Damp & Mould software at £125 + VAT per user per month (after a discounted £25 + VAT first month), with volume discounts for multiple users. HousingSurvey Pro starts free and its paid tiers run £29-£99 per surveyor per month. Always check each vendor's current pricing page before deciding — published prices change. Is PocketSurvey built specifically for housing associations? + No — PocketSurvey is a general building-surveying platform (an app designer and template editor) used across several inspection sectors, with a damp & mould module aimed partly at Awaab's Law reporting. HousingSurvey Pro is built specifically for housing associations, councils and their repairs contractors, with CMS integration (API, webhooks, EDI, SFTP) as a core feature rather than an add-on. ## Compared to paper & spreadsheets [vs paper & spreadsheets →](https://housingsurvey.pro/vs/paper-and-spreadsheets/) Can we just keep using paper forms and a spreadsheet for damp and mould evidence? + You can, and many landlords still do today — but a spreadsheet or a scanned form has no tamper-evidence: any editable file can be changed after the fact with no trace, which is precisely what the Housing Ombudsman and disrepair claims scrutinise. A purpose-built evidence system doesn't replace your surveyor's judgement, but it timestamps and locks the record the moment it's finalised. What's the real risk of sticking with spreadsheets under Awaab's Law? + Not the deadlines themselves — a well-run team can hit those with a spreadsheet. The risk is proving it later: a disrepair claim or Ombudsman complaint often arrives months after the event, and a record that anyone could have edited in the meantime is weaker evidence than one that was locked and hash-chained on the day. Didn't find your question? [Contact us](https://housingsurvey.pro/contact/) or search the [help centre](https://housingsurvey.pro/help/). Awaab's Law answers on this page are general information, not legal advice. Statutory timescales are being phased in by hazard type — always confirm current requirements with your compliance team. --- ## Developers — API, Webhooks, EDI, SCIM | HousingSurvey Pro Source: https://housingsurvey.pro/developers/ # Developers Everything technical lives here — your compliance and housing teams never need it, your integration team never needs anything else. Keys, webhooks and EDI are configured self-serve in the [management portal](https://portal.housingsurvey.pro) (Integrations, org-admin role, Platform plan and above). [Interactive API reference (Swagger)](https://housingsurvey.pro/api/docs/)[OpenAPI 3.0 spec](https://housingsurvey.pro/api/openapi.yaml) ## REST API v1 Base URL https://api.housingsurvey.pro/v1 · auth Authorization: Bearer hsp_live_… (scoped, revocable, hash-stored). Every read is written to your append-only audit log — integration access is itself evidence. GET /surveys HACT-aligned evidence list. Filters status , updatedSince ; cursor pagination. GET /surveys/:id One record + its chain block ( recordHash , prevRecordHash , chainSeq , finalizedAt ). GET /properties UPRN-keyed stock register with last-survey rollups. POST /work-orders Push a case to the field. Link the property by uprn (preferred), propertyId , or free-text address — unknown UPRNs 404 rather than creating unlinked orders. Statutory Awaab's Law deadlines stamp server-side. GET / POST /contractors Sync your supply chain: rich contractor records with insurance/accreditation expiry; POST returns an invite code that binds the contractor's organisation when redeemed. « create a work order against a registered property » curl -X POST -H "Authorization: Bearer $KEY" -H "Content-Type: application/json" \ -d '{"uprn":"100012345678","externalRef":"CASE-48211","hazardSeverity":"significant", "description":"Tenant reports black mould in child's bedroom"}' \ https://api.housingsurvey.pro/v1/work-orders ## Webhooks — verify the signature survey.finalized and statutory-deadline events POST to your endpoint, HMAC-SHA256 signed. Compute the HMAC of the raw body with your signing secret and compare to x-hsp-signature . Failed deliveries retry for an hour. // Node.js const crypto = require('crypto'); function verify(rawBody, header, secret) { const expected = crypto.createHmac('sha256', secret).update(rawBody).digest('hex'); return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(header)); } ## EDI flat-file (CSV) For CMSs that ingest files rather than webhooks: nightly drops (02:00 UK) or on-demand exports. UTF-8, CRLF line endings, RFC 4180 quoting, one row per room reading. [Download a sample file →](https://housingsurvey.pro/samples/edi-output-example.csv) Column (in order) Meaning record_id Evidence record id uprn_or_property_id UPRN when resolved, else internal property id property_address Denormalised address inspection_date ISO 8601, device-recorded finalized_at ISO 8601, server-set at sealing inspector_ref Surveyor identifier performing_org Org that captured (landlord or contractor) work_order_ref Our work-order id external_ref YOUR CMS case/job id, echoed back room Room the reading belongs to damp_type e.g. Condensation, Rising, Penetrating rh_pct Relative humidity % temp_c Air temperature °C surface_temp_c Surface temperature °C wme_pct Wood moisture equivalent % dew_point_c Dew point °C observations Surveyor notes (quoted CSV) photo_hashes Semicolon-separated SHA-256 capture hashes record_hash The sealed record hash — verify against the API chain block chain_seq Position in that property’s evidence chain ## Import formats (sample files) Every import in the portal documents its layout inline and validates row-by-row against it. Prepare your data before you ever sign in: - [properties-example.csv](https://housingsurvey.pro/samples/properties-example.csv) — uprn, addressLine1/2, postcode, localAuthority, tenureType, archetype (UPRN keys the evidence chain; rows without one import flagged for review) - [team-invites-example.csv](https://housingsurvey.pro/samples/team-invites-example.csv) — email, name, role ( surveyor / manager / org-admin , mixed freely per row) - [contractors-example.csv](https://housingsurvey.pro/samples/contractors-example.csv) — full supply-chain records incl. trades, regions, insurance and expiry dates All parsers are BOM/CRLF/quoting tolerant and match columns by header name in any order; required fields are strict, with per-row errors that cite the documented layout. ## SCIM 2.0 provisioning Enterprise plan: point Entra ID (or Okta) provisioning at your per-org SCIM endpoint (minted in the portal with a bearer token shown once). Joiners arrive as surveyors with seats enforced; deactivations disable access instantly — evidence is never deleted. ## Calendar feeds (iCal) Per-surveyor read-only iCal URLs: scheduled visits with one-hour alarms plus statutory deadlines as all-day events. Subscribe in Outlook/Google/Apple Calendar from the portal's app-linking step. ## Power Automate The [OpenAPI definition](https://housingsurvey.pro/api/openapi.yaml) imports directly as a custom connector — wire finalized evidence into Dynamics, SharePoint or Teams without code. Non-technical documentation lives in the [help centre](https://housingsurvey.pro/help/). Stuck? [Contact us](https://housingsurvey.pro/contact/) (support@prosurvey.app) — you'll never have to talk to us, but you can. --- ## Book a Demo | HousingSurvey Pro Source: https://housingsurvey.pro/demo/ # See it end to end Thirty minutes: a live capture in the field app, the record locking and chaining, the evidence landing in a CMS via webhook, and the portal your compliance team would live in. Bring your IT lead — we like hard questions. Don't want to wait for a call? [Try the live self-serve demo now](https://demo.housingsurvey.pro) — no sign-up, a synthetic organisation spun up instantly in your browser. What's this about? Sales & demos General enquiry Procurement / invoicing Support (existing customer) Leave this field empty Request demo --- ## Contact | HousingSurvey Pro Source: https://housingsurvey.pro/contact/ # Contact Send us a message and we'll route it to the right inbox — sales and demos, procurement or invoicing questions, integration and security questionnaires, or support if you're already a customer. We reply within 2 business days on every category, faster on support. What's this about? Sales & demos General enquiry Procurement / invoicing Support (existing customer) Leave this field empty Send message LinkedIn: [HousingSurvey Pro](https://www.linkedin.com/company/housingsurvey-pro) Existing customer support inbox: support@prosurvey.app (also reachable via the form above, "Support" category). HousingSurvey Pro is a product of ProSurvey Apps Limited (company no. 17118570), registered in England and Wales — the team behind [DampApp Pro](https://dampsurvey.pro) and [PropertySurvey Pro](https://propertysurvey.pro). --- ## Awaab's Law Evidence Requirements Explained | HousingSurvey Pro Source: https://housingsurvey.pro/awaabs-law/ # Awaab's Law changed what "we inspected it" has to mean. Awaab Ishak died in 2020 from prolonged exposure to mould in his family's social home. The law that carries his name — introduced through the Social Housing (Regulation) Act 2023, with Scotland following — sets fixed timescales for social landlords to investigate and fix damp and mould hazards. Free tool Know your statutory deadlines in seconds: enter an awareness date and get the investigate, written-summary, fix and emergency dates for your case. [Open the deadline calculator →](https://housingsurvey.pro/awaabs-law/deadline-calculator/) ## Built on the reformed HHSRS (2026) — the language your governance already speaks From 23 June 2026 the Housing Health and Safety Rating System was overhauled: 21 hazard profiles in four themes, three plain bands (High = Category 1 at a score of 1,000+, Medium, Low), renamed classes of harm and new baseline indicators. HousingSurvey Pro has the full 2026 assessment built into the field app — surveyors pick the hazard profile, record their likelihood and harm-outcome judgements, and the published formula scores and bands the hazard on the spot, sealed into the tamper-evident record. And because Awaab's Law timescales attach to hazards in phases, the app tells the surveyor live whether the hazard they're assessing is inside statutory deadlines today, scheduled for a coming phase, or an emergency on the 24-hour track — with both statutory tracks (working-day and emergency) tracked stage by stage: investigate, written summary, works begin. ## The compliance question is an evidence question Deadlines are only half the requirement. When a tenant complaint reaches the Housing Ombudsman, the questions are: when did you know, when did you inspect, what did you find, what did you do — and can you prove any of that? Notes typed into a CMS weeks later, photos in a surveyor's camera roll, spreadsheets that anyone can edit — none of it is defensible. ## What defensible looks like - Contemporaneous — captured on site, at the time, geo-stamped to the property. - Complete — readings, observations and fingerprinted photos in one structured record, per home, over time. - Tamper-evident — locked on completion with a server-set timestamp; cryptographically chained so any alteration, by anyone, is detectable. - Traceable — an append-only audit trail from tenant report (work order) to locked evidence, with the statutory clock attached. - Portable — flows into your case-management system automatically, and exports as a signed evidence bundle when the ombudsman asks. That is precisely — and only — what HousingSurvey Pro does. ## Awaab's Law, by audience and by stage Whichever seat you're in, the requirement comes back to defensible evidence. These guides go deeper: - [Awaab's Law software for housing associations](https://housingsurvey.pro/awaabs-law/for-housing-associations/) — stock-wide statutory clocks and HMS/CMS integration. - [Awaab's Law for repairs contractors](https://housingsurvey.pro/awaabs-law/for-contractors/) — capture evidence inside your client's chain. - [The statutory timeline explained](https://housingsurvey.pro/awaabs-law/timeline/) — investigation, written summary, repair and the 24-hour emergency track. - [The written summary requirement](https://housingsurvey.pro/awaabs-law/written-summary/) — what it must contain, and the 3-working-day deadline. - [HHSRS damp & mould hazard scoring](https://housingsurvey.pro/awaabs-law/hhsrs-damp-and-mould/) — Category 1 vs 2, and what to evidence. - [The deadline calculator](https://housingsurvey.pro/awaabs-law/deadline-calculator/) — enter an awareness date and get the statutory damp and mould deadlines. - [The cost of getting it wrong](https://housingsurvey.pro/awaabs-law/roi/) — Ombudsman findings, disrepair claims and how evidence reduces them. - [How HousingSurvey Pro compares](https://housingsurvey.pro/vs/) — honest, sourced comparisons with AwaabSafe, PocketSurvey and paper & spreadsheets. [Start free — no card, no call](https://portal.housingsurvey.pro)[How the evidence chain works](https://housingsurvey.pro/features/) ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Statutory timescales are counted in working days, differ between nations, and are being phased in — always confirm current requirements with your compliance team. --- ## Awaab's Law Written Summary Requirements | HousingSurvey Pro Source: https://housingsurvey.pro/awaabs-law/written-summary/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / Written summary requirements # The Awaab's Law written summary, explained. The written summary is the step teams most often treat as a formality — and the one most likely to be checked later, because it's the tenant-facing proof that an investigation actually happened and reached a conclusion. Here's what it needs to contain, when it's due, and what "done" actually looks like as evidence. ## Work out your written-summary deadline for a real case Enter the date you became aware of the hazard and the calculator gives you the investigation, written-summary and make-safe dates together. [Open the Awaab's Law deadline calculator →](https://housingsurvey.pro/awaabs-law/deadline-calculator/) ## When it's due Within 3 working days of the investigation ending — not 3 working days from the original report. For a significant damp and mould hazard investigated within the standard 10 working days, that puts the written summary due by day 13 overall. The clock counts working days only, so weekends and bank holidays don't count against you — but they also don't buy extra time if you miscount them. ## What it must contain - What was investigated. The hazard reported and the inspection carried out in response. - What was found. The actual finding — a significant hazard identified, a lesser issue, or nothing meeting the threshold. Vague language ("assessed, no immediate concerns") is a weak record; specific findings are a strong one. - Why, if no action is being taken. If the investigation didn't identify a significant hazard, the summary must explain why — this is the step landlords most often skip, and the one that most damages credibility if a tenant complains later. - What happens next, if anything. Where a hazard was found, what work follows and roughly when — this hands off cleanly to the repair-window evidence. ## Who has to receive it — and how The tenant. Not a case management system, not an internal note — the person who reported the hazard needs to actually receive the written summary, and you need to be able to prove they did, and when. A letter, a portal message, or an email all work if the delivery and date are recorded against the same property case as the investigation. ## Why this step gets scrutinised The written summary is usually the tenant's first and only written confirmation that anything happened. If a case later reaches the Housing Ombudsman, "we investigated and it was fine" without a dated, specific written summary the tenant can point to is a weak position — even if the investigation itself was done properly. See [the full statutory timeline](https://housingsurvey.pro/awaabs-law/timeline/) for how this step fits with investigation, repair and the 24-hour emergency track. Sources: GOV.UK — [Awaab's Law: guidance for social landlords](https://www.gov.uk/government/publications/awaabs-law-guidance-for-social-landlords) and the [Awaab's Law collection](https://www.gov.uk/government/collections/awaabs-law-in-the-social-rented-sector). Timescales are being introduced in phases by hazard type; confirm the current figures for your case with your compliance team. [Capture and issue the written summary from the same record — start free](https://portal.housingsurvey.pro) ## More on Awaab's Law - [Awaab's Law & the evidence question (overview)](https://housingsurvey.pro/awaabs-law/) - [The full statutory timeline explained](https://housingsurvey.pro/awaabs-law/timeline/) - [HHSRS damp & mould hazard scoring, explained](https://housingsurvey.pro/awaabs-law/hhsrs-damp-and-mould/) - [The Awaab's Law deadline calculator](https://housingsurvey.pro/awaabs-law/deadline-calculator/) ## Frequently asked questions ### How long do we have to issue the written summary? Within 3 working days of the investigation ending — day 13 overall for a significant damp and mould hazard, counting from the 10 working days allowed to investigate. The clock runs on working days, so weekends and bank holidays don't count. ### Do we still have to issue a written summary if we find no hazard? Yes. Awaab's Law guidance is explicit that the tenant must receive a written summary even when the investigation finds no significant hazard — it must explain why no further action is being taken, not just confirm that action is happening. ### Does the written summary have to be a formal letter? GOV.UK guidance does not mandate a specific format, but it must be written, given to the tenant (not just logged internally), and dated so the 3-working-day clock is evidenced. Most landlords issue it as a letter or portal message referencing the case. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Statutory timescales are counted in working days, differ between nations, and are being phased in — always confirm current requirements with your compliance team. --- ## The Awaab's Law Statutory Timeline Explained | HousingSurvey Pro Source: https://housingsurvey.pro/awaabs-law/timeline/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / Statutory timeline # The Awaab's Law statutory timeline, explained. Awaab's Law gives statutory force to repair timescales through the implied term in section 10A of the Landlord and Tenant Act 1985, inserted by the Social Housing (Regulation) Act 2023. The timescales came into force for the social rented sector in England on 27 October 2025 , starting with emergency hazards and damp and mould, with further HHSRS hazards phased in during 2026 and 2027. Here is how the clock runs — and what you need to prove at each stage. ## Work out your deadlines for a real case Enter the date you became aware of a damp and mould hazard and get the statutory investigation, written-summary and make-safe dates — working days computed for you. [Open the Awaab's Law deadline calculator →](https://housingsurvey.pro/awaabs-law/deadline-calculator/) ## The two tracks Every reported hazard runs on one of two tracks. The standard track covers investigation, written summary and repair, counted in working days. The emergency track requires a significant and imminent risk to be made safe within 24 hours . A single case can move between tracks as severity becomes clear on inspection. ## Stage by stage - 1. Investigate. Once a hazard is reported, you must investigate within the statutory window. The evidence needed: the date the report was received, and a dated, geo-stamped inspection record of what was found. - 2. Written summary. You must give the tenant a written summary of the investigation findings. The evidence needed: the summary itself and the date it was issued, tied to the same property record. - 3. Begin repairs. Where a hazard is found, repairs must begin within a further set period. The evidence needed: the works instruction, start date, and completion record. - 4. Emergency make-safe (parallel). Any emergency hazard must be made safe within 24 hours, regardless of where the standard track has reached. The evidence needed: a time-stamped make-safe record. ## Why each stage needs a contemporaneous record A deadline you met but can't prove you met is, at the Housing Ombudsman, a deadline you may be treated as having missed. That's why HousingSurvey Pro attaches the statutory clock to the work order and captures a dated, tamper-evident record at every stage — so the timeline isn't just tracked, it's evidenced . See how this works for [housing associations](https://housingsurvey.pro/awaabs-law/for-housing-associations/) and [their contractors](https://housingsurvey.pro/awaabs-law/for-contractors/). Sources: GOV.UK — [Awaab's Law: guidance for social landlords](https://www.gov.uk/government/publications/awaabs-law-guidance-for-social-landlords). Timescales are being introduced in phases by hazard type; confirm the current figures for your hazard and tenure. [See the statutory clock in the portal — start free](https://portal.housingsurvey.pro) ## Frequently asked questions ### When did Awaab's Law come into force? The Awaab's Law timescales came into force for the social rented sector in England on 27 October 2025, initially covering emergency hazards and damp and mould. Further HHSRS hazard categories are phased in during 2026, with the remaining hazards (except overcrowding) following in 2027. The framework is confirmed to extend to the private rented sector through the Renters' Rights Act. ### Are the timescales counted in calendar days or working days? The investigation and repair windows are counted in working days, while the emergency make-safe obligation is counted in hours. Because the exact windows are being phased in by hazard type, always confirm the current statutory figures that apply to the specific hazard and tenure before relying on them. ### What are the stages of the Awaab's Law timeline? In broad terms: (1) investigate the reported hazard within the statutory window; (2) provide the tenant with a written summary of the findings; (3) begin repairs within a further set period; and, running in parallel, (4) make safe any emergency hazard within 24 hours. Each stage needs a dated, contemporaneous record to be demonstrable. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/info/tools/awaabs-law-timeline-calculator) This page is general information, not legal advice. Statutory timescales are counted in working days, differ between nations, and are being phased in — always confirm current requirements with your compliance team. --- ## Cost of Getting Awaab's Law Evidence Wrong | HousingSurvey Pro Source: https://housingsurvey.pro/awaabs-law/roi/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / The cost of getting it wrong # The cost of getting Awaab's Law evidence wrong. The compliance conversation usually starts with software cost. The more useful question is the cost of the alternative: what an association pays when a damp and mould case can't be defended with a contemporaneous, tamper-evident record. That number is almost always larger, and it recurs. ## Where the cost actually sits - Ombudsman findings & compensation — maladministration findings and orders where the association couldn't evidence timely, competent action. - Disrepair claims & legal fees — claims that settle or escalate because the record to rebut them doesn't exist or isn't credible. - Repeat visits & re-inspection — sending someone back because the first record was incomplete or unverifiable. - Regulatory scrutiny — consumer-standards attention from the Regulator of Social Housing. - Reputation — a case that becomes a headline when it could have been a closed, well-evidenced file. Every one of these is a cost of not being able to prove good practice — not of bad practice. That's the specific risk contemporaneous evidence removes. ## The honest ROI calculation We won't quote you a made-up multiple. The real return depends on your stock size, your current claim and complaint history, and how much staff time you spend today turning field notes into records. HousingSurvey Pro reduces cost on the inputs you can measure: avoided repeat visits, faster case closure because evidence is complete first time, lower disrepair exposure because records are defensible, and no retyping into the CMS. Pricing is transparent and per-surveyor — see the [pricing page](https://housingsurvey.pro/pricing/) to put real numbers against your own portfolio. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## More on Awaab's Law - [Awaab's Law & the evidence question (overview)](https://housingsurvey.pro/awaabs-law/) - [Awaab's Law for housing associations](https://housingsurvey.pro/awaabs-law/for-housing-associations/) - [Awaab's Law for repairs contractors](https://housingsurvey.pro/awaabs-law/for-contractors/) - [The Awaab's Law statutory timeline explained](https://housingsurvey.pro/awaabs-law/timeline/) - [The Awaab's Law deadline calculator](https://housingsurvey.pro/awaabs-law/deadline-calculator/) ## Frequently asked questions ### What does it actually cost to get Awaab's Law evidence wrong? The costs stack up in layers: Housing Ombudsman findings and compensation orders; disrepair claims and legal fees where records can't be produced; re-inspection and repeat visits when the original evidence is incomplete; regulatory scrutiny from the Regulator of Social Housing; and the reputational cost of a case that could have been defended with a contemporaneous record. None of these require the association to have done the wrong thing — only to be unable to prove it did the right thing. ### How is HousingSurvey Pro priced? Per surveyor, per month, billed to the organisation — no per-report fees and no app-store purchases. PO numbers, BACS/bank transfer and payment terms are a normal part of how we work with housing associations and councils. See the pricing page for tiers. ### Where do the savings come from? Mainly from avoided repeat visits and re-inspections, faster case handling because evidence is complete first time, reduced disrepair exposure because records are defensible, and staff time saved by not retyping field notes into the CMS. We don't publish a fabricated ROI figure — the honest calculation depends on your stock size, claim history and current process, and the pricing/case-handling inputs are all transparent. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-roi) This page is general information, not legal advice, and does not guarantee any particular financial outcome. Always confirm current statutory requirements with your compliance team. --- ## HHSRS Damp & Mould Hazard Scoring Explained | HousingSurvey Pro Source: https://housingsurvey.pro/awaabs-law/hhsrs-damp-and-mould/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / HHSRS damp & mould hazard scoring # HHSRS damp & mould hazard scoring, explained. Awaab's Law sets the deadlines; HHSRS (the Housing Health and Safety Rating System) is the methodology that decides how serious a damp or mould finding actually is. Understanding the scoring matters because it's what separates a Category 1 hazard — the ones with the hardest legal consequences — from a lower-risk finding that still needs recording and fixing, just without the same enforcement teeth. ## Category 1 vs Category 2 Every HHSRS hazard gets a numerical score. Category 1 is a score of 1,000 or above — local councils have a mandatory duty to take enforcement action once a Category 1 hazard is identified in social housing. Category 2 is anything scoring below 1,000, split into moderate and low risk bands, where enforcement is discretionary rather than mandatory. Damp and mould growth is assessed as its own hazard profile within this system. ## How the score is actually calculated The hazard score combines two judgements, each made by the assessor on-site: - Likelihood of harm — the probability of a harmful outcome occurring in the next 12 months, assessed against the most vulnerable age group a home of that type could plausibly house, not necessarily the actual current occupant. - Severity of harm outcome — HHSRS classifies outcomes into four bands: Moderate, Serious, Severe and Extreme. GOV.UK guidance specifies harm must be "more serious than a minor scratch or bruise" to register at all. Those two figures feed a published formula to produce the final score. It's a structured, published methodology — but the judgement calls (what's actually observed, how likely it is to recur, how severe the plausible outcome is) remain the assessor's, not a mechanical output software can generate on its own. ## The 2026 reform, in one paragraph From 23 June 2026, HHSRS itself was overhauled: 21 hazard profiles grouped into four themes, three plain bands (High = Category 1 at 1,000+, Medium, Low) replacing some of the older terminology, and new baseline indicators — for damp and mould specifically, a stated baseline is "no room has observable damp or mould growth or deterioration of internal finishes exceeding 5% of the wall or ceiling surface." HousingSurvey Pro's field app has the full 2026 assessment built in, so surveyors work against the current methodology rather than a superseded one. ## Category 1 damp and mould vs the 24-hour emergency track These are related but not identical. A Category 1 HHSRS score means mandatory enforcement applies — it doesn't automatically mean the hazard is an Awaab's Law emergency . The 24-hour track is reserved for hazards presenting an imminent and significant risk of harm; a Category 1 finding that isn't imminent typically still follows the standard 10-working-day investigate / 3-day written-summary / 5-day make-safe track. Getting this distinction right on site is exactly the kind of judgement call that needs to be recorded, not just made. ## What to actually evidence - The specific observation — extent of mould/damp, affected surface percentage, room and location, not just "damp present". - The likelihood and harm-outcome judgement behind the score, in enough detail that someone reviewing the case later (a manager, an Ombudsman investigator, a solicitor) can see the reasoning, not just the number. - Dated, geo-stamped photos tied to the same property record as the score. - Which track the case is on (standard or emergency) and why. That record then flows straight into your housing management system (HMS) or case-management system — see [how integrations work](https://housingsurvey.pro/integrations/) — instead of being retyped from a paper checklist. Sources: GOV.UK — [Landlord and agent guide to HHSRS](https://www.gov.uk/government/publications/housing-health-and-safety-rating-system-hhsrs-landlord-and-agent-guide/landlord-and-agent-guide-to-the-housing-health-and-safety-rating-system-hhsrs) and [Awaab's Law: guidance for social landlords](https://www.gov.uk/government/publications/awaabs-law-guidance-for-social-landlords). HHSRS assessment is a professional discipline in its own right — this page is an orientation, not assessor training, and the 2026 reform is recent enough that assessor-level operating guidance should be your primary reference for edge cases. [Capture HHSRS-scored evidence in the field — start free](https://portal.housingsurvey.pro) ## More on Awaab's Law - [Awaab's Law & the evidence question (overview)](https://housingsurvey.pro/awaabs-law/) - [The full statutory timeline explained](https://housingsurvey.pro/awaabs-law/timeline/) - [The written summary requirement](https://housingsurvey.pro/awaabs-law/written-summary/) - [The Awaab's Law deadline calculator](https://housingsurvey.pro/awaabs-law/deadline-calculator/) ## Frequently asked questions ### What HHSRS category is damp and mould? Damp and mould growth is its own hazard profile under HHSRS. A hazard scores Category 1 (mandatory local-authority enforcement) at 1,000 points or above; below that it's Category 2 (moderate or low risk, discretionary enforcement). The score comes from the likelihood of harm over the next 12 months combined with the severity of the harm outcome, assessed against the most vulnerable plausible occupant age group, not just the actual tenant. ### Is a Category 1 HHSRS damp and mould hazard the same as an Awaab's Law emergency? Not automatically. Awaab's Law's 24-hour emergency track is for hazards presenting an imminent and significant risk of harm — a smaller, more urgent set than every Category 1 finding. A Category 1 damp and mould hazard that isn't imminent typically follows the standard 10/3/5-working-day track, not the 24-hour one. ### Who decides the HHSRS score — the software or the surveyor? The surveyor. HHSRS scoring is a professional judgement against a published methodology (likelihood and harm-outcome bands); software can structure the assessment and apply the published formula consistently, but the on-site judgement calls remain the surveyor's. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice, and is not a substitute for qualified HHSRS assessor training. Always confirm current methodology and requirements with your compliance team. --- ## Awaab's Law Software for Housing Associations | HousingSurvey Pro Source: https://housingsurvey.pro/awaabs-law/for-housing-associations/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / For housing associations # Awaab's Law compliance software for housing associations. Awaab's Law didn't just set deadlines — it changed the standard of proof. When a damp and mould case reaches the Housing Ombudsman, the association is asked when did you know, when did you inspect, what did you find, what did you do — and, crucially, can you prove it? HousingSurvey Pro is built so the answer is always yes, across your entire stock, whoever carried out the inspection. ## The statutory clock, running across every property at once The moment a tenant report is logged as a work order, the Awaab's Law clock starts. HousingSurvey Pro tracks both statutory tracks — the working-day track and the 24-hour emergency track — stage by stage (investigate → written summary → works begin) for every open hazard in your portfolio, so your compliance team sees what is inside deadline, what is approaching, and what has breached, in one view. See the [statutory timeline explained](https://housingsurvey.pro/awaabs-law/timeline/). ## Evidence your ombudsman can trust - Contemporaneous — captured on site, at the time, geo-stamped to the property by UPRN. - Tamper-evident — locked on completion, hash-chained per property so any later change is detectable. - Stock-wide — one portal across all your properties and all your contractors, not a folder per surveyor. - Portable — flows into your case-management system automatically, and exports as a signed evidence bundle on request. ## Fits the systems your IT team already runs HousingSurvey Pro is CMS-agnostic: a HACT-aligned REST API, signed webhooks, SFTP flat-file EDI, scheduled CSV exports and a Microsoft Power Automate connector mean it connects to NEC, Civica, MRI, Aareon and virtually any other system. Read more about [integrations](https://housingsurvey.pro/integrations/) and [security & data residency](https://housingsurvey.pro/security/). [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## More on Awaab's Law - [Awaab's Law & the evidence question (overview)](https://housingsurvey.pro/awaabs-law/) - [Awaab's Law for repairs contractors](https://housingsurvey.pro/awaabs-law/for-contractors/) - [The Awaab's Law statutory timeline explained](https://housingsurvey.pro/awaabs-law/timeline/) - [The cost of getting Awaab's Law evidence wrong](https://housingsurvey.pro/awaabs-law/roi/) ## Frequently asked questions ### What does Awaab's Law require a housing association to do? For the social rented sector in England, Awaab's Law requires you to investigate a reported damp and mould hazard within a fixed period, give the tenant a written summary of the findings, and begin repairs within a further set period — with emergency hazards made safe within 24 hours. The duties came into force on 27 October 2025 for emergency hazards and damp and mould, with further HHSRS hazards phased in through 2026 and 2027. The clock and the evidence are both your responsibility to demonstrate. ### Why isn't our case-management system enough on its own? A CMS records what your staff typed and when they saved it — which is editable after the fact and carries little evidential weight at the Housing Ombudsman. What defends the association is the contemporaneous field record: captured on site at the time, geo-stamped to the property, and provably unaltered since. HousingSurvey Pro produces that record and then feeds it into your CMS, so you keep your system of record and gain a defensible system of evidence. ### Can our repairs contractors capture evidence against our stock? Yes. Contractor organisations work under scoped grants from the landlord: their operatives capture evidence against your properties (by UPRN), and every finalized record belongs to your evidence chain, not theirs. You see the whole stock in one portal regardless of who did the inspection. ### How does it prove a record hasn't been altered? Finalized records are locked server-side with an authoritative timestamp, hash-chained to the previous record for the same property, and covered by an append-only audit log. A verification sweep recomputes every chain nightly, and exported evidence bundles carry the chain proof — so neither a contractor, nor a member of staff, nor even we can alter history undetectably. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Statutory timescales are counted in working days, differ between nations, and are being phased in — always confirm current requirements with your compliance team. --- ## Awaab's Law for Repairs Contractors | HousingSurvey Pro Source: https://housingsurvey.pro/awaabs-law/for-contractors/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / For contractors # Awaab's Law for repairs contractors. If you deliver damp and mould works for housing associations or councils, Awaab's Law is now part of your contract whether it names you or not. The landlord carries the statutory duty — but the evidence that proves it was met is created at the property, by the person who attends. That's you. HousingSurvey Pro lets you capture that evidence to a defensible standard and drop it straight into your client's compliance chain. ## Work inside your client's evidence chain Your organisation is granted scoped access to a landlord's stock. Your operatives capture geo-stamped, tamper-evident records against those properties by UPRN — and each finalized record becomes part of the landlord's chain, visible to their compliance team in real time. No more emailing photos, no more "can you resend the report", no dispute about when the work was done. ## Protect your contract and your reputation - On time — the statutory clock is visible to you too, so you never unknowingly miss a landlord's deadline. - To standard — structured capture means every job is evidenced the same defensible way. - Provable — a contemporaneous, tamper-evident record that you attended and what you did, independent of the landlord's system. [Start free — no card, no call](https://portal.housingsurvey.pro)[Try the live demo](https://demo.housingsurvey.pro) ## More on Awaab's Law - [Awaab's Law & the evidence question (overview)](https://housingsurvey.pro/awaabs-law/) - [Awaab's Law for housing associations](https://housingsurvey.pro/awaabs-law/for-housing-associations/) - [The Awaab's Law statutory timeline explained](https://housingsurvey.pro/awaabs-law/timeline/) - [The cost of getting Awaab's Law evidence wrong](https://housingsurvey.pro/awaabs-law/roi/) ## Frequently asked questions ### We're a repairs contractor, not the landlord — does Awaab's Law affect us? The statutory duty sits with the landlord, but in practice the evidence is created by whoever attends the property — and that's usually you. If your inspection records aren't contemporaneous and defensible, the association can't demonstrate compliance, which puts your contract and your reputation at risk. Increasingly, associations require their contractors to capture evidence to a defined standard. ### How does a contractor work inside a landlord's evidence chain? Your organisation is granted scoped access to the landlord's properties. Your operatives capture geo-stamped, tamper-evident records against those properties by UPRN, and each finalized record becomes part of the landlord's chain — visible to them in their portal in real time. You demonstrate the work was done, on time, to standard, without emailing photos around. ### Do we need a separate subscription per landlord we work for? No. Your surveyors capture against whichever landlord has granted your organisation access; the evidence lands in the relevant landlord's chain automatically. It's the same field app and the same workflow whether you're on one association's stock or several. ### What does this give us that the landlord's portal doesn't? A contractor-side record that you attended, when, and what you found and did — provably unaltered — so that if a case is scrutinised later, your position is defensible independently of the landlord's system. It's the difference between 'we say we fixed it' and 'here is the contemporaneous, tamper-evident proof'. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/awaabs-law-guide) This page is general information, not legal advice. Statutory timescales are counted in working days, differ between nations, and are being phased in — always confirm current requirements with the landlord and your own advisers. --- ## Awaab's Law Deadline Calculator | HousingSurvey Pro Source: https://housingsurvey.pro/awaabs-law/deadline-calculator/ [Awaab's Law](https://housingsurvey.pro/awaabs-law/) / Deadline calculator # Awaab's Law deadline calculator For social landlords and their contractors: enter the date you became aware of a damp & mould hazard to see the statutory deadlines that apply in the social rented sector in England from 27 October 2025 — investigation, written summary and make-safe, with the 24-hour emergency track. ## Hazard details Date you became aware of the hazard The clock starts when the landlord first becomes aware of the potential hazard. This is an emergency hazard e.g. serious leak, electrical danger, gas safety issue, or risk of collapse — a significant and imminent risk of harm. Select a date to calculate the statutory deadlines. Working days exclude weekends. England & Wales bank holidays are also excluded under the guidance — add any that fall within the window. This tool is for planning only and is not legal advice. ## Scope & sources Awaab's Law gives statutory force to repair timescales via the implied term in section 10A of the Landlord and Tenant Act 1985, inserted by the Social Housing (Regulation) Act 2023. The timescales above came into force for the social rented sector in England on 27 October 2025 , initially covering emergency hazards and damp & mould. Further hazard categories are phased in during 2026, with the remaining HHSRS hazards (except overcrowding) following in 2027. The government has confirmed the framework will be extended to the private rented sector through the Renters' Rights Act. Sources: GOV.UK — [Awaab's Law: guidance for social landlords](https://www.gov.uk/government/publications/awaabs-law-guidance-for-social-landlords/awaabs-law-guidance-for-social-landlords-timeframes-for-repairs-in-the-social-rented-sector) and the [27 October 2025 announcement](https://www.gov.uk/government/news/awaabs-law-to-force-landlords-to-fix-dangerous-homes). See also [the statutory timeline explained](https://housingsurvey.pro/awaabs-law/timeline/) and our [Awaab's Law overview](https://housingsurvey.pro/awaabs-law/). ## Knowing the deadline is half the duty. Proving you met it is the other half. HousingSurvey Pro attaches this statutory clock to the work order and captures a dated, geo-stamped, tamper-evident record at every stage — investigation, written summary, make-safe — so the timeline isn't just tracked, it's evidenced. [Start free — no card, no call](https://portal.housingsurvey.pro)[How associations use it](https://housingsurvey.pro/awaabs-law/for-housing-associations/) ## Frequently asked questions ### What are the Awaab's Law timescales for damp and mould? From 27 October 2025, social landlords in England must investigate a significant damp and mould hazard within 10 working days of becoming aware, provide a written summary of findings within 3 working days of the investigation ending, and make the property safe within 5 working days of the investigation. Emergency hazards must be made safe within 24 hours. ### What counts as an emergency hazard under Awaab's Law? An emergency hazard is one that presents an imminent and significant risk of harm — for example a serious leak, electrical danger, gas safety issue or risk of collapse. These must be investigated and made safe as soon as reasonably practicable and within 24 hours. ### Does Awaab's Law apply to private landlords? The 27 October 2025 timescales apply to the social rented sector in England. The government has confirmed the Renters' Rights Act will extend Awaab's Law to the private rented sector, with further hazards phased in during 2026 and 2027. ## Are you an independent surveyor, not a housing association? HousingSurvey Pro is built for organisations running Awaab's Law compliance across a whole stock — statutory clocks, work orders, a central management portal and case-management integration (NEC, Civica, MRI, Aareon and more). If instead you're a sole practitioner or independent damp & mould surveyor producing reports one property at a time, our sister app DampApp Pro is built for exactly that job. [See DampApp Pro for independent surveyors →](https://dampsurvey.pro/info/tools/awaabs-law-timeline-calculator) Working days exclude weekends; England & Wales bank holidays are also excluded under the guidance — add any that fall within the window. This tool is for planning only and is not legal advice. Statutory timescales are being phased in by hazard type — always confirm current requirements with your compliance team. --- ## For AI Agents — MCP Server & API Access | HousingSurvey Pro Source: https://housingsurvey.pro/agents/ # HousingSurvey Pro for AI agents HousingSurvey Pro runs a Model Context Protocol (MCP) server alongside its REST API v1, so AI agents and answer engines can read work orders and evidence, verify a record's tamper-evident hash, and raise or assign work — all under the same organisation-scoped permissions a human integrator gets, and all written to your append-only audit log. MCP endpoint https://api.housingsurvey.pro/mcp JSON-RPC 2.0 · streamable-http · protocol 2025-06-18 REST API v1 base https://api.housingsurvey.pro/v1 Sandbox: api-demo.housingsurvey.pro ## Authentication Bearer authentication with an organisation API key: Authorization: Bearer hsp_live_... An org-admin mints the key in the [management portal](https://portal.housingsurvey.pro) under Integrations → API keys , choosing least-privilege scopes. Keys are shown once, stored only as a hash, and revocable instantly. The full model — and why we publish an honest oauth-protected-resource without a delegated authorization server — is documented in [auth.md](https://housingsurvey.pro/auth.md). ## Available tools Tool Scope What it does list_work_orders work-orders:read List this organisation's work orders. Optional: status, jobType, limit (max 200). read_work_order work-orders:read Read one work order by id, including statutory-clock stage timestamps. raise_work_order work-orders:write Create a work order (property by uprn/propertyId/address, description, dueBy, jobType). assign_work_order work-orders:write Assign an existing work order to a surveyor already in your organisation. list_evidence surveys:read List finalized survey records (evidence) for a work order or the whole organisation. verify_record_hash surveys:read Re-derive a finalized survey's hash server-side and confirm it matches the stored chain — proves the record is untampered. get_contact_and_data_rights none How to contact us and how an organisation exercises data rights. No scope required. ## Machine-readable discovery - [MCP Server Card](https://housingsurvey.pro/.well-known/mcp/server-card.json) (SEP-1649) — also mirrored at [/.well-known/mcp.json](https://housingsurvey.pro/.well-known/mcp.json) - [Agent Skills index](https://housingsurvey.pro/.well-known/agent-skills/index.json) (agentskills.io v0.2.0) - [OAuth Protected Resource metadata](https://housingsurvey.pro/.well-known/oauth-protected-resource) (RFC 9728) - [API Catalog](https://housingsurvey.pro/.well-known/api-catalog) (RFC 9727 linkset) - [OpenAPI 3.0 spec](https://api.housingsurvey.pro/openapi.yaml) · [Swagger UI](https://housingsurvey.pro/api/docs/) - [auth.md](https://housingsurvey.pro/auth.md) — agent authentication & access metadata - [payments.md](https://housingsurvey.pro/payments.md) — payments & agentic commerce for agents - [llms.txt](https://housingsurvey.pro/llms.txt) · [llms-full.txt](https://housingsurvey.pro/llms-full.txt) ## Payments & agentic commerce HousingSurvey Pro is sold by subscription (per-surveyor GBP seats), not as a retail catalogue — there's no shopping cart and no agent-executable purchase endpoint. Checkout is Stripe-hosted and always completed by a human; billing has no REST or MCP route at all. We deliberately don't publish discovery documents for x402, MPP, UCP, ACP or AP2 today, and never will for x402 specifically (no cryptocurrency, stablecoin or walletrail, full stop) — the honest reasoning for each, protocol by protocol, is at [/payments.md](https://housingsurvey.pro/payments.md). ## Also part of the ProSurvey Apps family The sister app [DampApp Pro](https://dampsurvey.pro/agents) exposes its own agent interface for the independent-surveyor workflow. HousingSurvey Pro is the organisation-scale platform for housing associations, councils and their contractors. ## Frequently asked questions ### How does an agent authenticate to the HousingSurvey Pro MCP server? With an organisation API key as a bearer token (Authorization: Bearer hsp_live_…), minted by an org-admin in the management portal under Integrations → API keys and scoped to exactly what the integration needs. The MCP tools enforce the same scopes as REST API v1, and every call is written to the organisation's append-only audit log. Full detail: https://housingsurvey.pro/auth.md ### What can the MCP server do? Read work orders and their statutory-clock timestamps, list finalized evidence, verify a record's tamper-evident hash, and raise or assign work orders — all scoped. It is a read-and-safely-act server, not a bulk-export firehose. ### Where are the machine-readable descriptors? MCP server card at /.well-known/mcp/server-card.json (also mirrored at /.well-known/mcp.json), Agent Skills index at /.well-known/agent-skills/index.json, OAuth Protected Resource metadata at /.well-known/oauth-protected-resource, API Catalog at /.well-known/api-catalog, and the OpenAPI 3.0 spec at https://api.housingsurvey.pro/openapi.yaml. ### Can an agent buy or upgrade a plan directly? No. Neither REST API v1 nor the MCP server has a billing route or tool — access is read-and-safely-act against an already-provisioned organisation only. Buying, upgrading and seat changes are Stripe-hosted checkout actions a human completes in the management portal. Full detail, including why agentic-commerce discovery protocols like x402, MPP, UCP, ACP and AP2 aren't published on this domain, is at https://housingsurvey.pro/payments.md. [Full developer documentation →](https://housingsurvey.pro/developers/) --- ## About — ProSurvey Apps | HousingSurvey Pro Source: https://housingsurvey.pro/about/ # About HousingSurvey Pro is built by ProSurvey Apps Limited (company no. 17118570), the UK team behind [DampApp Pro](https://dampsurvey.pro) and [PropertySurvey Pro](https://propertysurvey.pro) — field survey software used daily by damp, timber and property professionals. After Awaab's Law, housing associations told us the same thing: they don't need another report generator — their case-management system does reports. They need evidence : contemporaneous, tamper-evident, integrated. So we took the survey science engine our surveyor apps are built on — psychrometrics, IAQ scoring, HHSRS, condensation analysis — and rebuilt the storage layer around a single idea: any change to a sealed record must be detectable, and the record must flow into whatever system you already run. Everything is self-serve by design — pricing on the page, checkout with a card, SSO and SCIM you configure yourselves — because we've sat on the other side of enterprise sales cycles too. --- ## API overview: authentication, integrity model, webhooks, testing Source: https://housingsurvey.pro/developers/ Evidence integration API for housing case-management systems: pull HACT-aligned, tamper-evident damp & mould evidence records, and push work orders to the field. Integrity model. Finalized records are locked server-side and hash-chained per property (UPRN): recordHash is the SHA-256 of the record's canonical JSON concatenated with the previous record's hash for the same property (prevRecordHash, chainSeq). Any alteration anywhere in the timeline is detectable, and a nightly verifier recomputes every chain. Auditing. Every API call is written to the organisation's append-only, hash-chained audit log — integration access is itself evidence. Webhooks. Configure an endpoint in the portal (Integrations) and receive a survey.finalized POST the moment a record locks. Bodies are HMAC-SHA256 signed: x-hsp-signature is the hex HMAC of the raw request body using your signing secret (shown once at setup); x-hsp-event names the event. Failed deliveries are retried for one hour. Payload shape: WebhookSurveyFinalized in the schemas below. Testing. Every integration is self-serve testable before you rely on it: the portal's "Send test event" button fires a real, x-hsp-signature- signed test.ping event at your configured webhook URL immediately (no queue, no waiting for a real survey), and shows the exact JSON body and headers your endpoint received. A "Quick start" panel next to the API key section gives copy-paste curl examples for this API, and a sample HACT payload viewer shows the full response shape using synthetic data. See the handbook's Integrations — Testing your connection guide for the full walkthrough (webhook, API, EDI, SMTP and AI provider checks). Report versions. A revised report is never edited in place — the original stays sealed and hash-chained, and a new record is created that supersedes it. Every survey carries lineageId (stable across every version — the original record's own id), versionNo (1-based, incrementing) and supersedes (the id of the version it replaces; null on the original). Key stored reports by lineageId and treat the highest versionNo as current. Example survey.finalized body for version 3 of a report: ``json { "event": "survey.finalized", "orgId": "org_4b7e1a", "surveyId": "svy_1e88bb", "recordHash": "3f9e2c1a7b…", "chainSeq": 12, "lineageId": "svy_9f2a01", "versionNo": 3, "supersedes": "svy_c77d40" } ` The nightly EDI CSV export carries the same lineage as version_no and supersedes columns alongside its existing record_hash/chain_seq` columns. Residency. All endpoints and data live in europe-west2 (London). --- ## API endpoints: Evidence Source: https://housingsurvey.pro/developers/ REST API v1 endpoints — Evidence: GET /surveys — List evidence records GET /surveys/{surveyId} — Get one evidence record with chain proof Full interactive reference: https://housingsurvey.pro/api/docs/ · OpenAPI spec: https://housingsurvey.pro/api/openapi.yaml --- ## API endpoints: Properties Source: https://housingsurvey.pro/developers/ REST API v1 endpoints — Properties: GET /properties — List properties Full interactive reference: https://housingsurvey.pro/api/docs/ · OpenAPI spec: https://housingsurvey.pro/api/openapi.yaml --- ## API endpoints: Contractors Source: https://housingsurvey.pro/developers/ REST API v1 endpoints — Contractors: GET /contractors — List your contractor directory POST /contractors — Add a contractor to your directory Full interactive reference: https://housingsurvey.pro/api/docs/ · OpenAPI spec: https://housingsurvey.pro/api/openapi.yaml --- ## API endpoints: Work orders Source: https://housingsurvey.pro/developers/ REST API v1 endpoints — Work orders: GET /work-orders — Poll your work orders and their statutory clocks POST /work-orders — Push a damp/mould case to the field GET /work-orders/{workOrderId} — Get one work order with its full statutory clock Full interactive reference: https://housingsurvey.pro/api/docs/ · OpenAPI spec: https://housingsurvey.pro/api/openapi.yaml