Security
Security you can explain to your owners.
Propiqo holds rent rolls, bank details and client money. Here is exactly how we protect it. No badges we haven't earned.
Access control
- Two-factor authentication with authenticator-app codes for staff accounts.
- 10 staff roles with granular permissions, enforced on every page and every API call.
- Property and portfolio scoping, so staff see only the buildings they manage.
- Tenants, owners and vendors use separate portal sessions that can never reach the staff app.
- Changing a user's role or deactivating them takes effect on their next request.
Data protection
- Every record belongs to one account, and every query is filtered by it. Cross-account access is covered by automated tests.
- Payment and messaging provider credentials are encrypted at rest.
- Passwords are hashed; sign-in attempts are rate limited.
- Security headers on every response, and HTTPS enforced in production.
- Financial records are never hard-deleted, so history stays intact.
Accountability
- An audit log records who changed what, when, from where, with the before and after values.
- Payments, bounces, payouts and approvals each leave a trail on the record they touched.
- Public links for payments, e-signatures and shared reports use unguessable tokens.
Your data stays yours
- Export any report to Excel.
- Read and write your data through the REST API, and receive webhooks on changes.
- Import from CSV when you arrive; take everything with you if you leave.
Found a vulnerability? Email support@propiqo.com and we'll respond promptly.
Put your portfolio on one system this week.
Start free with up to 2 units, or book a demo and we'll walk through your portfolio with you.