Security

We treat tenant data like it’s our own.

Encrypted end-to-end, auditable action by action, and built so a human always stays accountable.

Six commitments

The promises we make, before we write a line of code.

Security posture stated plainly, then the exact practice behind it — no claims we can’t defend in a vendor review.

  1. A human always stays accountable.

    Work orders need staff approval before a vendor is dispatched. Ambiguous calls route to the assigned property manager with full context.

  2. Your tenant data never trains a foundation model.

    Conversations, rent rolls, and work-order content are used for inference only — never sent to model providers for training or fine-tuning.

  3. Every decision is auditable end-to-end.

    Each tool call, classification, and outbound message is logged with timestamps, inputs, and outcomes. Exportable on request.

  4. Access is scoped by default.

    Role-based permissions for PMs, regional managers, and portfolio execs. Every action attributes to a named user on a named property.

  5. Encrypted in transit and at rest.

    TLS on every web, SMS, voice, and email connection. Tenant data and conversation history encrypted on managed cloud storage.

  6. Aligned with SOC 2 controls.

    Our program is modeled on SOC 2 control families. We do not claim certifications we have not earned — current status available on request.

How it actually works

Three controls doing most of the work.

  • Inference

    Tenant data flows through the model, not into it.

    Requests hit the model provider under zero-retention terms and return without being persisted on their side for training.

  • Guardrails

    Compliance is enforced before the model answers.

    TCPA keywords (STOP, START, HELP) are intercepted architecturally. Fair Housing is enforced in-prompt and validated by a post-generation classifier.

  • Trail

    Every Clara action writes an audit row.

    Tool calls, approvals, escalations, and outbound messages persist with full context. SSO and IP allow-listing available for enterprise on request.

What’s in place

The boring list procurement asks for.

  • Authentication

    Better Auth sessions with magic-link + Google OAuth; session tokens scoped to the HTTP-only cookie and validated server-side on every request.

  • Role-based access

    Every action scoped to the property and team it belongs to. Regional manager sees their region; site manager sees their building. No reads outside the properties in your role.

  • Encryption in transit & at rest

    TLS 1.2+ on every public endpoint; AES-256 on DynamoDB + S3 via AWS-managed KMS keys. No plaintext storage of PII or PHI-adjacent fields.

  • Immutable audit log

    Every classification, tool call, outbound message, and staff approval logged with who / when / why. Exportable on request when procurement asks.

  • Secrets management

    AWS SSM Parameter Store for all credentials. No secrets in code, no secrets in env files shipped to clients, rotation on suspected exposure.

  • Abuse & rate limits

    Per-sender and per-IP rate limits on every inbound webhook. STOP / HELP SMS keywords intercepted deterministically before reaching Clara.

  • Tenant data scoping

    Conversations, rent rolls, and work-order content belong to the property they came from. Clara does not mix tenant threads across companies or properties.

  • No model training

    Customer data is used for inference only — never sent to model providers for training or fine-tuning. Contract language available on request.

Enterprise ready

Enterprise-ready from day one

Integrates with your existing PMS. Scales with your portfolio. Deploys in days, not months. Every Clara interaction is TCPA compliant, Fair Housing aware, and fully auditable.

Compliance

  • TCPA Compliant
  • Fair Housing Compliant
  • Complete Audit Trail

Security

  • Zero Training Data
  • End-to-End Encryption
  • Role-Based Access
  • Human-in-the-Loop

Deployment

  • No Rip-and-Replace
  • Rapid Deployment
  • Portfolio-Level Dashboards
  • PMS Integrations

FAQ

What buyers, ask.

Do you train on our tenant data?

No. Conversations, rent rolls, lease details, and work-order content are never used to train foundation models. Data flows through the model for inference only and stays inside your infrastructure.

How is our data encrypted?

TLS for every inbound and outbound connection — web, SMS, voice, and email. At rest, tenant data and conversation history are encrypted on managed cloud storage using industry-standard algorithms.

Can I see what Clara did and why?

Yes. Every tool call, classification, and outbound message is logged with timestamps, inputs, and outcomes. The audit trail is exportable and scoped to your portfolio.

Can Clara act without a human approving?

Work orders require staff approval before a vendor is dispatched. Ambiguous, novel, or sensitive cases are escalated to the assigned property manager with full context already gathered.

Are you SOC 2 or HIPAA certified?

We align our program to SOC 2 control families and are working toward formal attestation. We do not claim certifications we have not earned — if you need specific attestations for a vendor review, talk to our security team about current status and timelines.

Do you sign DPAs and respond to security questionnaires?

Yes. Our current subprocessor list is published in our Privacy Policy. Email security@propflowai.co for our DPA and responses to SIG / CAIQ questionnaires.

How do you scope access inside an organization?

Role-based access controls scope every action to the property and team it belongs to. Magic-link and Google OAuth sign-in through Better Auth; SSO and IP allow-listing available for enterprise customers.

How do you handle TCPA and Fair Housing?

TCPA keyword handling (STOP, START, HELP) is intercepted architecturally, ahead of any model inference. Fair Housing guardrails are enforced in the prompts and validated by a post-generation classifier before any message leaves the system.

Running a vendor review? We’ll meet you there.

DPAs, questionnaire responses, and sub-processor change alerts on request. The current subprocessor list is published in our Privacy Policy.

Run your portfolio
on autopilot

Go from managing your operations to scaling them.

Book a demo

Hi, I’m Clara. How can I help?