Founding beta · 20 spots, 14 still open — get 12 months of Pro, free. Apply →

    Security

    Your data security is our highest priority. Here's how we protect your information.

    Encryption

    In Transit

    All data transmitted between your device and our servers is encrypted using TLS 1.3 (Transport Layer Security).

    At Rest

    All stored data, including property information, documents, and photos, is encrypted using AES-256 encryption.

    Backups

    Database backups are encrypted and stored in geographically separate locations.

    Infrastructure

    Cloud Hosting

    Hosted on Microsoft Azure — an enterprise-grade platform used by Australian banks, government, and Fortune 500 businesses.

    Data Residency

    Primary data is stored in Azure's Australia East region, so your property information stays on Australian soil.

    Backups

    Automated daily encrypted backups with point-in-time recovery. We've never lost a customer's data and we never intend to.

    Monitoring

    Continuous infrastructure monitoring with automated alerts. When something looks off, we hear about it before you do.

    Application Security

    Authentication

    Secure authentication with support for multi-factor authentication (MFA), Google Sign-In, and Apple Sign-In.

    Row-Level Security

    Database-level security policies ensure users can only access their own data.

    Input Validation

    All user inputs are validated and sanitised to prevent injection attacks.

    CSRF Protection

    Cross-site request forgery protection on all state-changing operations.

    Rate Limiting

    API rate limiting to prevent abuse and denial-of-service attacks.

    Privacy by Design

    Minimal Collection

    We collect only the data necessary to provide the Service.

    No Data Sales

    We never sell your personal information to third parties.

    Data Portability

    You can export or delete your data at any time.

    Access Logging

    Access to customer data by our team is logged, restricted, and requires justification.

    Compliance

    Australian Privacy Act 1988

    Full compliance with the Australian Privacy Principles (APPs).

    Notifiable Data Breaches

    We comply with mandatory data breach notification requirements under Part IIIC of the Privacy Act.

    PCI DSS

    Payment processing is handled by Stripe, a PCI DSS Level 1 certified provider.

    Vulnerability Reporting

    We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:

    • • Email: support@propally.com.au
    • • Please include a detailed description of the vulnerability and steps to reproduce it.
    • • We will acknowledge receipt within 48 hours and provide a resolution timeline.
    • • We will not take legal action against researchers who act in good faith.