Back

Security

We built SouthLet to be a safe place for the details of your home. This page describes what we do to protect your data, what we do not do yet, and how to report a problem.

How your account is protected

  • Email and password sign-in, plus Google and Apple sign-in.
  • Password reset by email.
  • Password change from Settings, which is recorded in the internal security log.
  • Sign-out clears your session and the app's local caches on the device.
  • Temporary account lockout after repeated failed sign-in attempts.
  • Strong password rules enforced when you create or change your password.
  • Per-account limits on scanning and assistant requests, to prevent abuse.
  • Browser security headers, including a content security policy, on every page.

Known gaps

Two-factor authentication with an authenticator app is available and can be switched on in Settings, but it is optional rather than required, so accounts without it rely on a password alone. There are no self-service recovery codes: if you lose your authenticator app you will need to contact support so we can verify who you are.

The internal security log is now cleared automatically: a scheduled daily job deletes entries 180 days after they are recorded. Some technical processing arrangements depend on the service providers used to operate SouthLet. We will provide further details where required by applicable data-protection law.

Report a security issue

If you believe you have found a security vulnerability in SouthLet, please email us at support@southlet.com. We treat every report seriously and will respond as quickly as we can. Please do not publicly disclose a vulnerability until we have had a chance to fix it.

More information