Security & privacy

Rental records are sensitive. We treat them that way.

Applications carry identity documents and income proof; leases and payments carry financial history. Here is how access is limited and recorded.

Organization isolation
Every customer record is scoped to an organization and enforced in the database itself, not just in the interface. A user only reads rows their membership permits.
Private file storage
Documents, bills and maintenance photos live in private buckets. Files are served through short-lived signed links generated only after an authorization check.
Roles and least privilege
Roles are stored separately from profiles. Property managers see assigned properties, tenants see their own tenancy, and contractors see only their assigned jobs — never tenants, rent or leases.
Append-only activity history
Approvals, role changes, lease changes, recorded payments, utility postings, announcements and deletions are written to an activity record customers cannot edit or remove.
Support access is explicit
Our staff cannot quietly browse your workspace. Support access is a time-limited session with a stated reason, a visible banner, and start and end entries in your log.
Retention you control
Declined and withdrawn application documents enter a retention queue and prompt deletion after a configurable period. Your local legal requirements always determine the final policy.

This page describes how the product is built today. It is not a certification claim, a compliance attestation or legal advice. If you need specific contractual or regulatory commitments, contact us and we will answer directly.