For regulated conveyancing firms

Security & Compliance

How the platform is run, how access is controlled, and how client data is handled.

Role-based access controls

HomeFlo uses identity-backed accounts and per-user roles. A user can hold one or more roles, and each role controls what they can see and do inside a case.

  • SolicitorCan create, manage and progress cases, issue documents and invite other parties.
  • BuyerCan view the case progress, upload documents and respond to requests related to their purchase.
  • SellerCan view the case progress and provide documents related to their sale.

Role assignments are stored separately from user profiles and are checked server-side on every protected request. Only authenticated users can access case data, and they can only access cases they have been invited to.

Case visibility and invitations

Cases are not publicly discoverable. A buyer or seller can only join a case through an invitation link or token generated by the solicitor handling the matter. Each invitation is scoped to a single case and can be tied to a specific email address.

Audit trail and logging

HomeFlo is designed to produce a clear, stage-by-stage record of every transaction. Each case shows when stages move forward and who updated the case. This gives firms a structured timeline that can be reviewed for compliance and dispute resolution.

Platform-level errors and security events are logged and reported so issues can be investigated quickly. Firms should still maintain their own internal file notes and client correspondence records as required by their regulator.

Data handling and retention

Case data is stored in the backend database associated with each firm’s account. HomeFlo retains client conveyancing data for between 5 and 21 years after completion, depending on the case type and the firm’s regulatory obligations.

Firms are responsible for deciding the exact retention period that applies to each matter and for securely deleting or archiving data once it is no longer needed. Please contact the app owner if you need a record removed or exported.

Encryption and authentication

All traffic between the browser and the platform is encrypted in transit using TLS. Authentication is handled through Lovable Cloud with industry-standard session management, including password hashing and secure tokens.

Firms should enforce strong passwords, prompt sign-out on shared devices, and follow their own IT security policies when accessing client data.

Hosting and subprocessors

HomeFlo is built on the Lovable Cloud platform. No additional third-party subprocessors are used beyond the Lovable Cloud infrastructure, which includes managed backend, authentication and database services.

Compliance posture

HomeFlo is designed to support the day-to-day compliance needs of UK conveyancing practices by keeping case information organised, access controlled and progress visible. The platform does not currently hold a formal security certification such as Cyber Essentials or ISO 27001. A Data Processing Agreement is not currently offered as a standard document.

Firms remain responsible for their own regulatory compliance, including SRA accounts rules, data protection obligations, anti-money laundering checks and client confidentiality.

Security contact

If you discover a security issue or have a compliance question, please email the app owner. Reports are reviewed and acknowledged as soon as possible.

security@homeflo.co.uk

Shared responsibility: Lovable Cloud provides the underlying platform, hosting and authentication infrastructure. The HomeFlo app owner configures the application, manages roles, sets data-handling practices and responds to security questions. Each firm is responsible for its own use of the platform, user training, client consent and regulatory compliance.