Secure & encrypted
How MoveLane keeps your data secure
What encryption, hosting and access controls we use, and how you can check them yourself.
Encryption in transit
Every page, form submission and API call on movelane.co.uk is served over HTTPS (TLS). Requests to the plain HTTP address are redirected to the encrypted address, so credentials, enquiry details and payment session requests are never sent in the clear.
Certificates are issued and renewed automatically by our hosting platform, so there is no window where the site is served on an expired certificate.
Encryption at rest and hosting
Accounts, listings, enquiries and uploaded media are stored in our managed cloud database and object storage, both encrypted at rest by the platform. Uploaded documents such as agency verification evidence are held in a private storage bucket that is not publicly listable and is only served through short-lived signed links.
Backups are managed by the hosting platform and are encrypted with the same protections as the live data.
Access control inside the product
Database access is enforced per row: a signed-in user can read and change their own profile, saved properties and alerts, an agency user can only see listings and enquiries belonging to their agency, and administrative pages require an account holding an admin role stored in a separate roles table.
Enquiry records contain personal contact details, so they are never readable by anonymous visitors — only the agency the enquiry was sent to and MoveLane administrators can open them.
Evidence you can expect to see
- The padlock in your browser's address bar on every MoveLane page, with the certificate issued to movelane.co.uk.
- Signing out and trying to open /account, /agent or /admin: you are redirected to sign-in rather than shown any data.
- Signing in as an agency user and confirming only your own agency's listings and enquiries appear in the agent portal.
- Agency documents you upload are not reachable from a plain public URL — links expire.
What this does not claim
- This page describes controls we operate ourselves. It is not an independent audit, penetration test result or security certification.
- We do not claim to be SOC 2, ISO 27001 or Cyber Essentials certified. If we obtain a certification we will name it here.
This article is maintained by MoveLane to answer common security, privacy and billing questions. It is not an independent certification, audit or legal advice.
Other trust articles
Card data never reaches MoveLane. Here is exactly what Stripe holds, what we hold, and what you can see.
What we collect, how consent is enforced before analytics loads, and how to exercise your data rights.
Monthly billing, no minimum term, self-service cancellation, and what happens to your listings afterwards.
The Companies House check, the documents we ask for, and precisely what a verified badge does and does not mean.
Who answers, when, where AI is used, how escalation to a person happens, and what response times to expect.
