Security

How we protect your building's data, in plain English.

Encryption

TLS 1.3 in transit. AES-256 at rest. Bcrypt password hashing with a work factor of 12.

Infrastructure

Hosted on Vercel and Neon (both SOC 2 Type II). Cloudflare DDoS protection in front. DB backups every 6h.

Access control

Strict tenant isolation. Residents only see their unit's data. Cross-org access is impossible by design.

Payments

We never store card or bank account numbers. Stripe handles all payment data (PCI DSS Level 1).

Account security

Mandatory MFA (TOTP) for admins, accountants, and property managers. 12+ character password minimum. bcrypt hashing. Login rate limiting to block brute force.

Session security

Auto sign-out after 2 hours of inactivity with a 5-minute warning. Secure HTTP-only session cookies. Sign-out clears all cached pages so the back button can't reveal logged-in content.

Certifications & audits

StandardStatusNotes
SOC 2 Type IIIn progressTarget: Q3 2026
Penetration testScheduledAnnual third-party test
PCI DSSCovered via StripeWe never touch card data
GDPR / CCPA / PIPEDACompliantSee our GDPR page
HIPAAN/AWe don't handle PHI

Reporting a security issue

If you've found something that looks like a security problem, email security@aedobuild.com with the details and please give us reasonable time to fix it before sharing publicly. Machine-readable contact info lives at /.well-known/security.txt (RFC 9116).

DDoS & abuse protection

We run behind Cloudflare with bot filtering, WAF managed rules, and rate limiting on sensitive endpoints (auth, signup). Vercel's infrastructure absorbs additional load.