Security & compliance

Built for Canadian data, from the ground up

Compliance isn’t a checkbox we added later β€” it’s in the architecture: where your data lives, how it’s scoped, and how every message and role is handled.

πŸ”’

Data residency in Canada

Your data is hosted in a Canadian region (ca-central-1) so it stays in the country β€” a deliberate choice for PIPEDA-aligned handling.

πŸ›‘οΈ

PIPEDA-aligned by design

We collect what’s needed to run your rentals, keep it scoped to your account, and treat personal information in line with PIPEDA principles.

βœ‰οΈ

CASL-compliant messaging

Every commercial email and SMS carries consent tracking and an unsubscribe path β€” consent is captured and honoured, not assumed.

πŸ‘₯

Role-based access control

Tenants, owners, managers, and admins each see only what their role allows β€” enforced on the server, not just hidden in the UI.

🏒

Strict account isolation

Every record is scoped to your account; cross-account access is a deliberate, audited platform-admin exception β€” never the default.

🧾

Audit trail

Sensitive views and actions are recorded, so there’s a clear history of who did what and when.

πŸ”‘

Secure authentication

Passwords are hashed, sessions are signed tokens, and email verification plus password reset are built in.

🍁

Province-aware rules

Deposit and rent-increase guidance follows the province β€” surfaced as tooling to help you stay onside (not legal advice).

PropaFlow surfaces provincial rules and tax tooling to help you operate with confidence, but it is tooling, not legal or accounting advice. For specific situations, consult a qualified professional.
Get started