Security
Last updated: August 17, 2026
LandGrantIQ handles sensitive right-of-way, condemnation, and landowner data. This page summarizes how the platform is designed and operated to protect it, and states plainly where work is still outstanding.
Data encryption
All traffic between your browser and the Service is encrypted with TLS. Customer data, documents, and backups are encrypted at rest using industry-standard algorithms managed by our cloud provider.
Access control
Access follows least privilege. Every user is assigned a role (landowner, land agent, counsel, operations, firm admin, or platform admin) that determines what they can see and do, and their role is carried in a signed token rather than asserted by the client. Role checks are applied to the application’s business endpoints; authentication is enforced globally by default-deny middleware. Data is scoped to the organization that owns it, and landowner and outside-counsel access is further limited to the specific parcels granted to them.
We are completing an audit of role and tenant enforcement across all application routes ahead of general availability, and we will publish the results. Pilot customers receive the current status in writing during security review.
Audit logging
Security-relevant events — sign-ins, document access, offer changes, and administrative actions — are recorded in immutable audit logs with actor, action, and timestamp, and are available to firm administrators.
Infrastructure
The Service runs on Google Cloud Platform, with network isolation between environments and managed platform patching. Production access by our engineers is limited, logged, and requires multi-factor authentication.
Backups and resilience
Data is backed up automatically on a regular schedule with point-in-time recovery, and backups are encrypted. We will begin testing restoration on a documented quarterly schedule before general availability, and will share the results of those tests with pilot customers on request.
Vulnerability management
Code changes go through review and an automated test suite before release. We will complete an independent security assessment before general availability and make the summary available under NDA.
Compliance status
We would rather be direct about where we are than imply more than we have. We do not hold a SOC 2 report today, and we do not hold ISO 27001 certification. LandGrantIQ is pre-general-availability and is being run as a controlled pilot product, and we will begin formal audit work when a customer commitment makes it meaningful rather than performative.
We complete customer security questionnaires, and we will walk your IT and security teams through the architecture, the access model, and the open items above during pilot scoping.
Responsible disclosure
If you believe you have found a security vulnerability in LandGrantIQ, please report it to security@landgrantiq.com. Include enough detail for us to reproduce the issue; we will acknowledge reports promptly and keep you informed as we investigate. Please do not access data that is not yours or degrade the Service while testing.
Questions
For security questionnaires, compliance documentation, or other inquiries, contact security@landgrantiq.com.