Security & trust

Property data deserves enterprise security. We start there.

Every PII field encrypted. Every write logged. Every byte resident in the GCC. Built so the largest UAE landlord can use it without losing sleep.

SOC 2

Roadmap · audit prep in motion

PII encryption

AES-256-GCM at rest

Data residency

AWS me-south-1 (Bahrain) default

Audit logging

Every write captured

UAE PDPL aware

Data subject rights as features

Penetration testing

Annual external test planned

How we protect personal data

Every PII field — Emirates ID, passport number, IBAN, salary, owner phone — is encrypted with AES-256-GCM before it ever touches the database. Encryption keys are managed in AWS KMS and never leave the cloud HSM.

Tenant-facing UIs only display the last four characters by default; a full read requires an additional auth challenge logged to the audit trail. Even a database leak would give an attacker nothing useful.

Where your data lives

All production data is stored in the AWS me-south-1 region (Bahrain). Backups are encrypted, geo-replicated within the same region, and retained for 30 days.

On the Enterprise tier we can pin specific workspaces to AWS me-central-1 (UAE Dubai) on request, with no impact on platform features. This is offered to government and DLD-linked customers as part of the standard contract.

Audit log — every write, every time

Every create, update, or delete that touches a financial or tenancy record is logged with: userId, workspaceId, action, entityType, entityId, before/after snapshot, IP address, user-agent and timestamp.

Audit logs are append-only. They're retained for five years to comply with the UAE Commercial Companies Law commercial record retention requirements. You can export the full audit log of your workspace as JSON at any time, on any tier.

UAE PDPL data subject rights

Federal Decree-Law 45/2021 (UAE PDPL) sets out nine data subject rights — access, correction, deletion, portability, restriction, and more. PropertyPad surfaces these as platform features rather than ticket workflows.

A tenant can request a data export from their portal. A deletion request flows to a structured workflow, with financial records retained per the UAE Commercial Companies Law and PII redacted.

The team behind your data

PropertyPad is built and operated by a team based in Dubai. Access to customer data follows the principle of least privilege — production access is restricted to a small number of named engineers, with every access logged.

We do not sell or share customer data. We do not train AI models on customer data without explicit opt-in.

Need to dig deeper?

Request our security questionnaire pack.

Includes SIG Lite, CAIQ Lite, sub-processor list, recent pen-test summary and our incident response runbook. Sent within one business day to security@propertypad.ae verified domains.

Request security pack