Encryption
In Transit
All data transmitted between your device and our servers is encrypted using TLS 1.3 (Transport Layer Security).
At Rest
All stored data, including property information, documents, and photos, is encrypted using AES-256 encryption.
Backups
Database backups are encrypted and stored in geographically separate locations.
Infrastructure
Cloud Hosting
Hosted on Microsoft Azure — an enterprise-grade platform used by Australian banks, government, and Fortune 500 businesses.
Data Residency
Primary data is stored in Azure's Australia East region, so your property information stays on Australian soil.
Backups
Automated daily encrypted backups with point-in-time recovery. We've never lost a customer's data and we never intend to.
Monitoring
Continuous infrastructure monitoring with automated alerts. When something looks off, we hear about it before you do.
Application Security
Authentication
Secure authentication with support for multi-factor authentication (MFA), Google Sign-In, and Apple Sign-In.
Row-Level Security
Database-level security policies ensure users can only access their own data.
Input Validation
All user inputs are validated and sanitised to prevent injection attacks.
CSRF Protection
Cross-site request forgery protection on all state-changing operations.
Rate Limiting
API rate limiting to prevent abuse and denial-of-service attacks.
Privacy by Design
Minimal Collection
We collect only the data necessary to provide the Service.
No Data Sales
We never sell your personal information to third parties.
Data Portability
You can export or delete your data at any time.
Access Logging
Access to customer data by our team is logged, restricted, and requires justification.
Compliance
Australian Privacy Act 1988
Full compliance with the Australian Privacy Principles (APPs).
Notifiable Data Breaches
We comply with mandatory data breach notification requirements under Part IIIC of the Privacy Act.
PCI DSS
Payment processing is handled by Stripe, a PCI DSS Level 1 certified provider.
Vulnerability Reporting
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:
- • Email: support@propally.com.au
- • Please include a detailed description of the vulnerability and steps to reproduce it.
- • We will acknowledge receipt within 48 hours and provide a resolution timeline.
- • We will not take legal action against researchers who act in good faith.