Security practices for property data
These are the controls our systems and processes are designed to support. We describe them plainly, including where they fall short of an independently verified certification, rather than claiming compliance we have not undergone.
Least privilege access
Encryption in transit
Encryption at rest
Secure, expiring object links
Access logging
Tenant and project separation
Backups
Retention controls
What happens if something goes wrong
- Suspected incidents are triaged immediately: scope, affected records, and access paths are identified first.
- Affected clients are notified with what is known, what is being done, and what remains under investigation, as required by the engagement contract and applicable law.
- Access credentials or links implicated in an incident are revoked or rotated as part of containment.
- A written summary of cause and remediation is produced once the investigation is closed.
SuiteDash and other vendor boundaries
Commercial relationship data — proposals, contracts, invoices, messages, and support tickets — is held in SuiteDash, a third-party CRM platform, under its own security practices and our contractual terms with it. Property capture data is not stored in SuiteDash and is not duplicated across systems.
No raw technical files in GitHub
No secrets in the browser
Report a security concern
If you believe you have found a security issue affecting our systems or a client's property data, tell us before disclosing it publicly.
Contact for security reports
For how captured property data itself is divided, minimized, and retained, see data handling. For the broader picture of how we establish trust, see trust.
Have a security requirement for an engagement?
Tell us your requirements up front and we will tell you plainly what we can and cannot commit to.