Security
Last updated: July 26, 2026
Portier369 manages sensitive financial and personal data for community associations. Protecting that data is foundational to the platform. This page summarizes the measures we use; we are happy to discuss specifics with prospective Customers under NDA.
Tenant isolation
Every database query is governed by row-level security enforced at the database layer. Access is scoped to a user's portfolio and role, so one management company can never access another's data, and owners, board members, and vendors only see what their role permits.
Access control
Accounts are invitation-based and role-based, following the principle of least privilege. Administrative and platform-operator actions are separated from association accounting, and sensitive operations are recorded in an audit trail. We encourage strong, unique credentials and are expanding multi-factor authentication options.
Encryption
Data is encrypted in transit using industry-standard TLS and encrypted at rest by our infrastructure providers. Sensitive integration secrets are held in protected server-side configuration. Where online assessment payments are enabled, Stripe collects and tokenizes card or bank-account credentials through the association's own connected account. Portier369 stores processor identifiers and limited display details, not full homeowner card numbers, bank-account numbers, or online-banking credentials.
Banking data
Where a Customer connects a bank account for reconciliation, connectivity is provided by Plaid. Plaid holds the banking login credentials; Portier369 receives account and transaction data through access tokens and does not store online banking credentials. Reconciliation does not move money.
AI data processing
Optional AI features operate on a bring-your-own-key basis: when a Customer enables them, content such as uploaded documents or images is transmitted to the AI provider the Customer selected and configured with its own credentials, solely to produce the requested output. Customers control whether these features are enabled and which provider receives their data. See our Privacy Policy for details.
Infrastructure and certifications
The platform runs on established cloud infrastructure (including Supabase and Vercel) whose providers maintain their own industry-recognized security certifications, such as SOC 2. Portier369 does not yet hold its own independent certification; we describe our practices honestly and will update this page as our program matures.
Backups and recovery
The platform uses automated backups and point-in-time recovery so data can be restored after an incident. Backups are retained on a rolling schedule and aged out over time. Production resident data is not committed to source control.
Sub-processor security
We engage a limited set of sub-processors (listed in our Privacy Policy) and require them, by contract, to maintain security obligations consistent with those described here.
Incident response
We maintain an incident-response process. If a security incident affects Customer data, we will investigate, take steps to contain and remediate it, and notify affected Customers without undue delay, consistent with our Data Processing Addendum and applicable law.
Data portability
Your data belongs to you. Customers can export their records at any time, and there is no vendor lock-in on your association data.
Reporting a vulnerability
If you believe you have found a security issue, please contact us at hello@portier369.com with enough detail to reproduce it. We will acknowledge your report, investigate promptly, and keep you informed. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to remediate before public disclosure.
Security is an ongoing program, not a one-time state. This page describes current practices and may evolve as the platform grows.