Security
Built around dealership boundaries.
Customer records, inspection evidence, and billing are business data. This page describes, plainly, how MarineInspect is built to protect them today.
Dealer-level tenant isolation
Every customer, boat, inspection, and file belongs to one dealership. Access rules keep each dealership to its own records.
Role-based access
Dealer Admin, Manager, and Technician permissions are enforced on the server, not only in the app's interface.
Row-level security
Built on Supabase Postgres, with row-level security policies on dealership data and dealership-scoped server functions.
Private inspection media
Photos and videos are kept in private storage and are never published as open file links.
Secure customer video access
Customers watch through a MarineInspect page that grants short-lived access to each clip.
Controlled dealer administration
Only active Dealer Admins can use the web portal. Role and dealership can't be chosen from the browser.
One active device per user
Each account is bound to one phone at a time. A second phone is refused until a dealer admin releases the first.
Payments through Stripe
Card details are entered on Stripe-hosted pages. Prices are calculated on the server, never in the browser.
In detail
How the controls work.
Your dealership's data stays in your dealership
Every user profile belongs to exactly one dealership, and every customer, boat, inspection, checkpoint, and media file is tied to that dealership. Database row-level security policies use that boundary on every request, so a signed-in user can only ever read and change their own dealership's records.
The web portal and the mobile app follow the same rules. The portal is another client of the same database, not a separate system with its own copy of your data.
Permissions are enforced on the server
Dealer Admin, Manager, and Technician permissions are checked by the database and server functions, not only by hiding buttons. A technician can edit only their own open inspections; only a dealer admin can delete records or manage the team, billing, and storage.
Users can't choose their own role or dealership. Deactivated users lose access immediately, and each account can be active on one phone at a time.
Inspection media is private
Photos and videos are uploaded to private storage organized by dealership and inspection. They are never published as open, permanent links.
When a customer opens the Watch Inspection Videos link from their report, MarineInspect checks the link and grants short-lived access to each clip as it plays. Dealer admins can delete completed inspections, and their media, whenever they choose.
Payments are handled by Stripe
Card details are entered on Stripe-hosted Checkout and Customer Portal pages, and never touch MarineInspect's servers. Plan prices and seat totals are calculated on the server from the plan catalog; the browser can't change the amount charged.
Payment credentials are kept in server-side configuration and are never sent to the browser or the mobile app.
Certifications
MarineInspect does not currently claim SOC 2, ISO 27001, HIPAA, or other third-party certifications. If your dealership has a security questionnaire or specific requirements, contact us and we'll answer it directly.
Give your dealership a better way to inspect, document, and deliver.
Create a dealer admin account, choose a plan, and bring every inspection, photo, video, and report into one system.