Encryption
TLS 1.3 in transit. AES-256 at rest. Bcrypt password hashing with a work factor of 12.
Infrastructure
Hosted on Vercel and Neon (both SOC 2 Type II). Cloudflare DDoS protection in front. DB backups every 6h.
Access control
Strict tenant isolation. Residents only see their unit's data. Cross-org access is impossible by design.
Payments
We never store card or bank account numbers. Stripe handles all payment data (PCI DSS Level 1).
Account security
Mandatory MFA (TOTP) for admins, accountants, and property managers. 12+ character password minimum. bcrypt hashing. Login rate limiting to block brute force.
Session security
Auto sign-out after 2 hours of inactivity with a 5-minute warning. Secure HTTP-only session cookies. Sign-out clears all cached pages so the back button can't reveal logged-in content.
Certifications & audits
| Standard | Status | Notes |
|---|---|---|
| SOC 2 Type II | In progress | Target: Q3 2026 |
| Penetration test | Scheduled | Annual third-party test |
| PCI DSS | Covered via Stripe | We never touch card data |
| GDPR / CCPA / PIPEDA | Compliant | See our GDPR page |
| HIPAA | N/A | We don't handle PHI |
Reporting a security issue
If you've found something that looks like a security problem, email security@aedobuild.com with the details and please give us reasonable time to fix it before sharing publicly. Machine-readable contact info lives at /.well-known/security.txt (RFC 9116).
DDoS & abuse protection
We run behind Cloudflare with bot filtering, WAF managed rules, and rate limiting on sensitive endpoints (auth, signup). Vercel's infrastructure absorbs additional load.