Platform

Security and Administration

Who can see what, who did what, and where your data actually lives.

Book a walkthrough All features

Access control

Roles

Org admin, property manager, accountant, and maintenance, each seeing the part of the system their job needs.

Module permissions

Turn a whole module off for a role from a permissions matrix, without anybody editing code.

Per-property access

Scope a user to the properties they run. Lists, reports, and totals all narrow with them, so a report never quietly includes properties whose rows are hidden.

Menu access by role

Control what appears in the navigation per role, enforced again on the server rather than trusted to the hidden menu.

Separate portal logins

Tenant, vendor, and owner portals authenticate on their own scheme, entirely apart from staff accounts.

Accountability

Audit log

Created, updated, and deleted, with who and when, recorded once per business event rather than once per ledger line.

Sensitive values redacted

Bank and routing numbers, taxpayer IDs, and anything token-shaped are written to the audit log as redacted. An audit table is readable by more people than the records it describes.

Encrypted at rest

Bank account numbers and taxpayer IDs are encrypted in the database, not merely hidden in the interface.

Void, do not delete

Money moves are reversed rather than erased, so the history of a correction survives the correction.

How it is deployed

Your own instance

Each client gets their own application and their own database. Isolation between customers is physical rather than a filter somebody has to get right.

Multiple entities in one instance

Run several management companies or legal entities inside your own deployment, each with its own users and data.

Deliberate releases

A build tells you exactly what a database change would do; only a person starting a release actually applies it.

Self-hosted or cloud

Run it in Azure or on your own servers.

The boundary is the server, every time

Hiding a menu item is a convenience, not a security control. Every scope in this system — role, module, property, portal — is enforced where the data is read, so a hidden page and a forbidden one are the same thing.

Related

Platform Vendors