Trust
Security & Compliance
Last updated: August 26, 2026
Proppely, Inc. · Hollywood, FL
Proppely holds rent ledgers, lease documents, association records, resident personal information, and — when a user connects Gmail or Outlook — copies of that mailbox. This page describes the controls that protect it, in specific terms rather than reassurances. Where a certification belongs to one of our providers rather than to us, we say so. If your security team needs something not covered here, write to security@proppely.com. Google user data practices are also in Privacy — Google User Data.
1. Infrastructure & Independent Audits
Where Proppely runs
Proppely runs on Render (application and database) and Amazon Web Services (document storage, email delivery, and media). All infrastructure is located in the United States. We do not operate our own data centers.
Our providers’ audits
Render maintains a SOC 2 Type 2 attestation and ISO/IEC 27001 certification, and Amazon Web Services maintains SOC 1, SOC 2, SOC 3, ISO 27001, and PCI DSS Level 1 attestations. Render’s SOC 3 report is available on request. These are our providers’ audits, not ours.
Our own programme
Our security programme is documented rather than improvised. We maintain a written policy set covering access control, change management, incident response, and business continuity; a risk register that is scored and reviewed on a defined cadence; and control objectives describing how we process our customers’ financial transactions. We are working toward a SOC 2 examination, a SOC 1 examination, and ISO/IEC 27001 certification. We will name the firm and the report date here once an engagement is signed — an intention is not an audit, and we would rather you could check what we tell you.
What we can share
For security reviews we can provide our infrastructure providers’ publicly distributable reports, a completed vendor security questionnaire, our subprocessor list, and our PCI DSS self-assessment attestation. Reports we hold under NDA from our providers cannot be redistributed, but we can confirm in writing that we have reviewed them.
2. Payment Data & PCI DSS
Card and bank details never reach our systems
This is the most important fact about our security posture. Card numbers, security codes, and full bank account numbers are entered directly into our payment provider’s own hosted form, which runs in an isolated frame served from the provider’s domain. That data is transmitted to the provider and never passes through, and is never stored on, Proppely infrastructure. We receive only a payment token plus the card brand and last four digits.
Our PCI scope
Because all cardholder data functions are fully outsourced to a PCI DSS Level 1 validated provider, Proppely falls within the scope of PCI DSS Self-Assessment Questionnaire A — the shortest assessment, available to merchants who handle no cardholder data themselves. We do not describe ourselves as “PCI certified” or “PCI compliant”: SAQ A is a self-assessment, not a certification, and the meaningful fact is the one above — the data never reaches us.
Payment page integrity
The pages that host the payment frame carry a Content Security Policy that restricts executable scripts to an explicit allowlist of payment and mapping vendors. Analytics, tag managers, session replay, and advertising scripts are prohibited on the payment path, and adding a host to that allowlist is treated as a compliance change rather than a routine deployment.
No payments through chat
Money cannot be moved by messaging our assistant, and payment details are never entered in a chat channel. AI features that touch money can only propose an action that a human then confirms in the application.
3. Encryption & Secrets
In transit
All traffic between your browser or mobile app and our servers is encrypted using TLS 1.2 or higher. HTTP requests are redirected to HTTPS.
At rest
Data at rest — including the database, uploaded documents, and backups — is encrypted with AES-256 by our infrastructure providers.
Application-layer encryption for sensitive fields
Certain fields carry a second layer of encryption above the storage layer, including rental application identifiers and third-party integration credentials. Encryption keys are held in managed key storage separate from the database.
Connected mailbox tokens
Gmail and Outlook OAuth access and refresh tokens are encrypted at the application layer with AES-256-GCM before they are stored, in addition to the infrastructure encryption of the database at rest. We store imported message copies on our US-hosted database so /inbox can work when Gmail is not open. We do not copy Gmail attachments into object storage.
Passwords
Account passwords are hashed with Argon2, a memory-hard algorithm designed to resist offline cracking. Plaintext passwords are never stored or logged.
4. Access Control & Data Separation
Separation between organizations
Proppely is a multi-tenant platform. Every request is authenticated and bound to a single organization, and data access is scoped to that organization at the data-access layer so that one organization’s records cannot be returned to another. This scoping is enforced centrally rather than re-implemented per feature.
Roles inside your organization
Members hold explicit roles that determine what they can see and do. Each organization has a single account owner with supreme authority who cannot be removed by other members. Residents, owners, and vendors access their own portals and can never reach organization-wide data.
Connected Gmail and Outlook
A connected mailbox is bound to the user who authorized it. Teammates cannot open another user’s Gmail or Outlook copies. Owners, managers, and agents may connect their own accounts; tenants cannot. Unlink at Settings → Integrations → Email revokes the provider token and deletes that user’s Proppely copies. Native organization mail delivered through Amazon SES is a separate shared inbox and is not erased by unlinking Gmail.
Two-factor authentication
Accounts support time-based one-time password (TOTP) two-factor authentication with recovery codes. Sensitive authentication flows, including sign-in links, remain subject to the second factor.
Audit logging
Security-relevant and financially significant actions are recorded to an append-only audit log with the acting user, organization, timestamp, and affected record.
5. Data Retention & Deletion
You own your data
Records you enter remain yours. Financial reports, ledgers, documents, and rent rolls can be exported at any time in standard formats so that leaving Proppely never means losing your history.
Statutory retention for community associations
Florida community associations must keep official records for periods fixed by statute — generally seven years under Fla. Stat. §§ 718.111(12) and 720.303(4), with certain records required to be kept permanently. Proppely is built so that association records subject to those requirements are retained rather than aged out, and so that owner record requests can be satisfied from the platform.
Deletion
You may request deletion of your account and associated personal data at proppely.com/account-deletion. Unlinking a connected Gmail or Outlook mailbox deletes Proppely’s copies of that mailbox and revokes the OAuth token; mail inside Gmail or Outlook is unchanged. Deleting your Proppely login also disconnects those mailboxes. We may retain records where law requires it — tax and financial transaction records, and association official records within their statutory window — or where retention is necessary for fraud prevention. We will tell you what is retained and why.
6. AI Features & Your Data
Your data is not used to train models
Proppely does not use customer data to train machine learning models, and does not permit our model providers to do so. AI features send only the context needed to answer the request at hand. Connected Gmail and Outlook text may be sent as capped excerpts through OpenRouter solely to produce an inbox category, tags, and a one-line gist. We do not use that mail for advertising.
Restricted Gmail scopes
When Google requires a Cloud Application Security Assessment (CASA) for restricted Gmail scopes, we complete it with an authorized lab. We do not describe ourselves as CASA-validated until a lab has issued a Letter of Validation for this application.
Every write stays under human control
AI features can read your data and draft work, but actions that change records, move money, or send communications require explicit human approval before they take effect. Every tool the assistant can reach is classified by risk before it is enabled, and unclassified tools are denied by default.
Bring your own key
Organizations that prefer their data to travel under their own model-provider agreement can supply their own API key for the assistant, in which case assistant requests are billed to and governed by that agreement.
7. Availability & Recovery
Backups
The production database is backed up automatically by our infrastructure provider with point-in-time recovery. Documents are stored in versioned, redundant object storage. — CONFIRM exact frequency and retention window before publishing.
Monitoring
Application errors and exceptions are captured by an error monitoring service and reviewed. Infrastructure health and uptime are monitored by our hosting provider.
8. Reporting a Vulnerability
How to reach us
If you believe you have found a security vulnerability in Proppely, email security@proppely.com with enough detail to reproduce it. We will acknowledge your report and keep you informed as we investigate. We ask that you give us a reasonable opportunity to remediate before public disclosure, and we will not pursue action against good-faith research that respects user privacy and avoids service disruption. — CONFIRM this mailbox exists and is monitored.
Incident notification
If a security incident affects your data, we will notify you without unreasonable delay and describe what happened, what data was involved, and what we are doing about it, consistent with applicable breach-notification law including Fla. Stat. § 501.171.
9. Subprocessors
These vendors process customer data on our behalf under data processing agreements or equivalent contractual protections. Some are engaged only when you enable the corresponding feature.
| Vendor | Purpose | Data | Region |
|---|---|---|---|
| Render | Application and database hosting | All platform data | United States |
| Amazon Web Services | Document storage, email delivery, document text extraction, meeting media | Documents, email content, meeting recordings | United States |
| Moov Financial | Payment processing and payouts | Payment credentials, transaction data | United States |
| Payment processing partners | Owner distributions and screening fee processing | Payment credentials, transaction data | United States |
| Plaid | Bank account verification and transaction sync | Bank account and transaction data | United States |
| Checkr | Tenant background screening | Applicant identity and screening data | United States |
| TransUnion SmartMove | Tenant credit and background screening | Applicant identity and screening data | United States |
| DocuSign | Electronic signature (optional integration) | Documents sent for signature | United States |
| Sure | Renters insurance offering | Resident contact and policy data | United States |
| TaxBandits | 1099 preparation and filing | Vendor and owner tax identifiers | United States |
| Twilio | SMS account notifications (opt-in) | Phone number, message content | United States |
| Meta WhatsApp Cloud API | WhatsApp messaging channel (opt-in) | Phone number, message content | United States |
| Gmail API (optional Connect Gmail) | Authorized mailbox messages and send-as-user | United States | |
| OpenRouter | Routes AI inference, including inbox triage | Prompts and message excerpts | United States |
| Anthropic, OpenAI, DeepSeek, and other model providers | AI assistant, document understanding, and inbox classification | Context supplied to the request | United States |
| Sentry | Application error monitoring | Error traces and technical metadata | United States |
| Plausible | Privacy-preserving website analytics | Aggregate page views, no cookies | European Union |
| Mapbox | Maps and geocoding | Property addresses | United States |