Security and trust

It is money. Precision and restraint are the product.

The ledger is append-only

Nothing in Propertly’s ledger is ever edited in place. Corrections are reversing entries, and every prior state is preserved. The audit trail is immutable by construction, not by policy.

AI proposes. Humans approve.

There is no code path from an AI to a journal entry. Automation writes proposals; a property-accounting expert reviews and approves them, and only that approval materializes an entry. Every AI action is traceable and reversible.

Read-only on client money

We never hold or move your money on our own authority. Access to your property-management system and bank feeds is read-only.

Everything is logged

Every action — human, AI, or system — lands in an append-only audit log: who, what, when, and the before and after of every change.

Access discipline

Multi-factor authentication is mandatory for everyone. Access is scoped per client and enforced at the application layer and in the database itself. Every session and action is audited.

Compliance posture

We run SOC 2 practices from day one — MFA everywhere, least privilege, immutable audit logs, encrypted infrastructure — with certification on our roadmap. Our infrastructure providers hold SOC 2 Type II attestations.

Questions about the security model are welcome in a walkthrough.