Security Overview
Effective: 2026-10-05 Version: 2026.10.05
This overview describes our security approach. It does not replace or reduce obligations in an applicable signed agreement or Data Processing Addendum. Ask hello@getpropty.ai for current documentation relevant to your proposed use.
Encryption
We use encryption and access controls to protect information. The specific controls depend on the service, data and provider involved; this overview is not an assertion that every field is separately encrypted.
Access control
Application permissions restrict access by role and organization. Propty staff are required to use two-factor authentication. Customers should protect credentials, keep authorized-user access current and report suspected unauthorized access promptly. Specific privileged-access and logging controls should be confirmed through current security documentation rather than inferred from this overview.
Vulnerability management
We use software checks and security reports to identify issues for investigation. Report vulnerabilities through our bug bounty and responsible disclosure page, subject to that page's scope and rules. Do not access another person's information or disrupt the service while testing.
Certifications and regulated data
This page does not claim SOC 2, ISO 27001 or other independent certification. Request any current audit report directly from Propty before relying on it. Do not submit protected health information unless Propty has expressly agreed in writing to support that use and any required agreement is in place.
Payment security
Payment providers process payment information through the configured payment flow. Outsourcing payment processing does not automatically remove Propty's or an operator's applicable PCI DSS responsibilities. Scope and validation depend on the actual integration and the requirements of the relevant acquirer, payment brand and service providers. Do not send full card numbers or security codes through ordinary email, chat or support requests; use the designated payment flow.
Incident response
Propty uses Sentry and provides 24/7 incident and security monitoring and response. Report a suspected security incident to hello@getpropty.ai. We investigate reports and provide notices required by applicable law and our agreements. Monitoring and response do not guarantee that every incident is detected or resolved within a fixed time. This overview does not create a separate response-time guarantee or change an existing contractual notification deadline.
Subprocessor security
Our subprocessor list identifies service providers. The applicable DPA governs provider obligations and any required notice or objection process. Customers may request current information needed to evaluate their use of the service.
For specific security questions: hello@getpropty.ai