Property Portal

Security

How we protect the ledger

Last updated August 24, 2026.

Property Portal is built so the browser and phone apps are not the source of truth. The server checks who you are and what you may see before it returns or writes data.

Accounts

Sign-in uses hashed passwords (Convex Auth). Reset and new-device checks go out by email. Native apps keep session tokens in the platform keystore or Keychain, not in ordinary settings files.

Access

Roles are enforced in Convex: a guessed work-order id is not enough. Residents are limited to their units. Staff are limited to their company. Invites use unguessable tokens that expire.

Data in transit and at rest

The public site is HTTPS. API traffic goes to Convex over TLS. Photos live in Convex file storage on the work order they belong to.

Payments

Cards are handled by Stripe. We do not store full card numbers. Billing keys stay on the Convex deployment — they are not in the Netlify app or in the mobile binaries.

What we do not claim

We do not sell a formal audit badge (SOC 2, ISO 27001) on this page. If you need a vendor questionnaire for a company plan, write from the email on the owner account.