Security

How we protect your building's data, in plain English.

Encryption

TLS 1.3 in transit. AES-256 at rest. Bcrypt password hashing with a work factor of 12.

Infrastructure

Hosted on Vercel and Neon (both SOC 2 Type II). Cloudflare DDoS protection in front. DB backups every 6h.

Access control

Strict tenant isolation. Residents only see their unit's data. Cross-org access is impossible by design.

Payments

We never store card or bank account numbers. Stripe handles all payment data (PCI DSS Level 1).

Account security

Mandatory MFA (TOTP) for admins, accountants, and property managers. 12+ character password minimum. bcrypt hashing. Login rate limiting to block brute force.

Session security

Auto sign-out after 15 minutes of inactivity with a 1-minute warning. Secure HTTP-only session cookies. Sign-out clears all cached pages so the back button can't reveal logged-in content.

Certifications & audits

StandardStatusNotes
SOC 2 Type IIIn progressTarget: Q3 2026
Penetration testScheduledAnnual third-party test
PCI DSSCovered via StripeWe never touch card data
GDPR / CCPA / PIPEDACompliantSee our GDPR page
HIPAAN/AWe don't handle PHI

Bug bounty

We pay for responsibly disclosed bugs

Find a security issue? We pay $50–$5,000 depending on severity. Safe harbor for good-faith research.

See bug bounty program →

Vulnerability disclosure

Found a security issue? Email security@aedobuild.com. We respond within 24 business hours and acknowledge valid reports within 5 days.

Our policy follows RFC 9116 — see /.well-known/security.txt.

DDoS & abuse protection

We run behind Cloudflare with bot filtering, WAF managed rules, and rate limiting on sensitive endpoints (auth, signup). Vercel's infrastructure absorbs additional load.

Working on a security questionnaire? Email security@aedobuild.com and we'll fill it out within 3 business days.