$9.99/month · unlimited unitsSchedule a demo

Trust

Security & Compliance

Last updated: August 26, 2026

Proppely, Inc. · Hollywood, FL

Proppely holds rent ledgers, lease documents, association records, resident personal information, and — when a user connects Gmail or Outlook — copies of that mailbox. This page describes the controls that protect it, in specific terms rather than reassurances. Where a certification belongs to one of our providers rather than to us, we say so. If your security team needs something not covered here, write to security@proppely.com. Google user data practices are also in Privacy — Google User Data.

1. Infrastructure & Independent Audits

Where Proppely runs

Proppely runs on Render (application and database) and Amazon Web Services (document storage, email delivery, and media). All infrastructure is located in the United States. We do not operate our own data centers.

Our providers’ audits

Render maintains a SOC 2 Type 2 attestation and ISO/IEC 27001 certification, and Amazon Web Services maintains SOC 1, SOC 2, SOC 3, ISO 27001, and PCI DSS Level 1 attestations. Render’s SOC 3 report is available on request. These are our providers’ audits, not ours.

Our own programme

Our security programme is documented rather than improvised. We maintain a written policy set covering access control, change management, incident response, and business continuity; a risk register that is scored and reviewed on a defined cadence; and control objectives describing how we process our customers’ financial transactions. We are working toward a SOC 2 examination, a SOC 1 examination, and ISO/IEC 27001 certification. We will name the firm and the report date here once an engagement is signed — an intention is not an audit, and we would rather you could check what we tell you.

What we can share

For security reviews we can provide our infrastructure providers’ publicly distributable reports, a completed vendor security questionnaire, our subprocessor list, and our PCI DSS self-assessment attestation. Reports we hold under NDA from our providers cannot be redistributed, but we can confirm in writing that we have reviewed them.

2. Payment Data & PCI DSS

Card and bank details never reach our systems

This is the most important fact about our security posture. Card numbers, security codes, and full bank account numbers are entered directly into our payment provider’s own hosted form, which runs in an isolated frame served from the provider’s domain. That data is transmitted to the provider and never passes through, and is never stored on, Proppely infrastructure. We receive only a payment token plus the card brand and last four digits.

Our PCI scope

Because all cardholder data functions are fully outsourced to a PCI DSS Level 1 validated provider, Proppely falls within the scope of PCI DSS Self-Assessment Questionnaire A — the shortest assessment, available to merchants who handle no cardholder data themselves. We do not describe ourselves as “PCI certified” or “PCI compliant”: SAQ A is a self-assessment, not a certification, and the meaningful fact is the one above — the data never reaches us.

Payment page integrity

The pages that host the payment frame carry a Content Security Policy that restricts executable scripts to an explicit allowlist of payment and mapping vendors. Analytics, tag managers, session replay, and advertising scripts are prohibited on the payment path, and adding a host to that allowlist is treated as a compliance change rather than a routine deployment.

No payments through chat

Money cannot be moved by messaging our assistant, and payment details are never entered in a chat channel. AI features that touch money can only propose an action that a human then confirms in the application.

3. Encryption & Secrets

In transit

All traffic between your browser or mobile app and our servers is encrypted using TLS 1.2 or higher. HTTP requests are redirected to HTTPS.

At rest

Data at rest — including the database, uploaded documents, and backups — is encrypted with AES-256 by our infrastructure providers.

Application-layer encryption for sensitive fields

Certain fields carry a second layer of encryption above the storage layer, including rental application identifiers and third-party integration credentials. Encryption keys are held in managed key storage separate from the database.

Connected mailbox tokens

Gmail and Outlook OAuth access and refresh tokens are encrypted at the application layer with AES-256-GCM before they are stored, in addition to the infrastructure encryption of the database at rest. We store imported message copies on our US-hosted database so /inbox can work when Gmail is not open. We do not copy Gmail attachments into object storage.

Passwords

Account passwords are hashed with Argon2, a memory-hard algorithm designed to resist offline cracking. Plaintext passwords are never stored or logged.

4. Access Control & Data Separation

Separation between organizations

Proppely is a multi-tenant platform. Every request is authenticated and bound to a single organization, and data access is scoped to that organization at the data-access layer so that one organization’s records cannot be returned to another. This scoping is enforced centrally rather than re-implemented per feature.

Roles inside your organization

Members hold explicit roles that determine what they can see and do. Each organization has a single account owner with supreme authority who cannot be removed by other members. Residents, owners, and vendors access their own portals and can never reach organization-wide data.

Connected Gmail and Outlook

A connected mailbox is bound to the user who authorized it. Teammates cannot open another user’s Gmail or Outlook copies. Owners, managers, and agents may connect their own accounts; tenants cannot. Unlink at Settings → Integrations → Email revokes the provider token and deletes that user’s Proppely copies. Native organization mail delivered through Amazon SES is a separate shared inbox and is not erased by unlinking Gmail.

Two-factor authentication

Accounts support time-based one-time password (TOTP) two-factor authentication with recovery codes. Sensitive authentication flows, including sign-in links, remain subject to the second factor.

Audit logging

Security-relevant and financially significant actions are recorded to an append-only audit log with the acting user, organization, timestamp, and affected record.

5. Data Retention & Deletion

You own your data

Records you enter remain yours. Financial reports, ledgers, documents, and rent rolls can be exported at any time in standard formats so that leaving Proppely never means losing your history.

Statutory retention for community associations

Florida community associations must keep official records for periods fixed by statute — generally seven years under Fla. Stat. §§ 718.111(12) and 720.303(4), with certain records required to be kept permanently. Proppely is built so that association records subject to those requirements are retained rather than aged out, and so that owner record requests can be satisfied from the platform.

Deletion

You may request deletion of your account and associated personal data at proppely.com/account-deletion. Unlinking a connected Gmail or Outlook mailbox deletes Proppely’s copies of that mailbox and revokes the OAuth token; mail inside Gmail or Outlook is unchanged. Deleting your Proppely login also disconnects those mailboxes. We may retain records where law requires it — tax and financial transaction records, and association official records within their statutory window — or where retention is necessary for fraud prevention. We will tell you what is retained and why.

6. AI Features & Your Data

Your data is not used to train models

Proppely does not use customer data to train machine learning models, and does not permit our model providers to do so. AI features send only the context needed to answer the request at hand. Connected Gmail and Outlook text may be sent as capped excerpts through OpenRouter solely to produce an inbox category, tags, and a one-line gist. We do not use that mail for advertising.

Restricted Gmail scopes

When Google requires a Cloud Application Security Assessment (CASA) for restricted Gmail scopes, we complete it with an authorized lab. We do not describe ourselves as CASA-validated until a lab has issued a Letter of Validation for this application.

Every write stays under human control

AI features can read your data and draft work, but actions that change records, move money, or send communications require explicit human approval before they take effect. Every tool the assistant can reach is classified by risk before it is enabled, and unclassified tools are denied by default.

Bring your own key

Organizations that prefer their data to travel under their own model-provider agreement can supply their own API key for the assistant, in which case assistant requests are billed to and governed by that agreement.

7. Availability & Recovery

Backups

The production database is backed up automatically by our infrastructure provider with point-in-time recovery. Documents are stored in versioned, redundant object storage. — CONFIRM exact frequency and retention window before publishing.

Monitoring

Application errors and exceptions are captured by an error monitoring service and reviewed. Infrastructure health and uptime are monitored by our hosting provider.

8. Reporting a Vulnerability

How to reach us

If you believe you have found a security vulnerability in Proppely, email security@proppely.com with enough detail to reproduce it. We will acknowledge your report and keep you informed as we investigate. We ask that you give us a reasonable opportunity to remediate before public disclosure, and we will not pursue action against good-faith research that respects user privacy and avoids service disruption. — CONFIRM this mailbox exists and is monitored.

Incident notification

If a security incident affects your data, we will notify you without unreasonable delay and describe what happened, what data was involved, and what we are doing about it, consistent with applicable breach-notification law including Fla. Stat. § 501.171.

9. Subprocessors

These vendors process customer data on our behalf under data processing agreements or equivalent contractual protections. Some are engaged only when you enable the corresponding feature.

VendorPurposeDataRegion
RenderApplication and database hostingAll platform dataUnited States
Amazon Web ServicesDocument storage, email delivery, document text extraction, meeting mediaDocuments, email content, meeting recordingsUnited States
Moov FinancialPayment processing and payoutsPayment credentials, transaction dataUnited States
Payment processing partnersOwner distributions and screening fee processingPayment credentials, transaction dataUnited States
PlaidBank account verification and transaction syncBank account and transaction dataUnited States
CheckrTenant background screeningApplicant identity and screening dataUnited States
TransUnion SmartMoveTenant credit and background screeningApplicant identity and screening dataUnited States
DocuSignElectronic signature (optional integration)Documents sent for signatureUnited States
SureRenters insurance offeringResident contact and policy dataUnited States
TaxBandits1099 preparation and filingVendor and owner tax identifiersUnited States
TwilioSMS account notifications (opt-in)Phone number, message contentUnited States
Meta WhatsApp Cloud APIWhatsApp messaging channel (opt-in)Phone number, message contentUnited States
GoogleGmail API (optional Connect Gmail)Authorized mailbox messages and send-as-userUnited States
OpenRouterRoutes AI inference, including inbox triagePrompts and message excerptsUnited States
Anthropic, OpenAI, DeepSeek, and other model providersAI assistant, document understanding, and inbox classificationContext supplied to the requestUnited States
SentryApplication error monitoringError traces and technical metadataUnited States
PlausiblePrivacy-preserving website analyticsAggregate page views, no cookiesEuropean Union
MapboxMaps and geocodingProperty addressesUnited States