Security
Your portfolio data stays yours, and stays separated.
Keyloma holds leases, payments and resident records. These are the controls we put around them.
Organization isolation
Every record in Keyloma belongs to exactly one organization. Access rules are enforced in the database itself, not only in the interface, so a request for another company's data returns nothing — regardless of how it is made.
- Row-level rules applied to every table that holds company data
- Server-side checks on every read and write
- No shared records between companies
Role-based access
Staff see what their role allows. Owners and residents only ever see their own properties, leases and documents, and sharing a document with a resident is an explicit action.
- Distinct manager, staff, owner and resident access
- Document sharing is opt-in per file
- Invitations are scoped to a single organization
Activity history
Creates, edits, archives and AI-executed actions are written to an activity history you can review at any time. Nothing important is hard-deleted — records are archived so the trail stays intact.
- Who changed what, and when
- AI actions logged with rationale and approval
- Archive instead of delete for leases, payments and work orders
Encryption & backups
Data is encrypted in transit and at rest, and files are stored in private buckets reachable only through short-lived signed links. Managed database backups run continuously with point-in-time recovery available.
- TLS in transit, encryption at rest
- Private file storage with expiring access links
- Regular automated database backups
Data ownership & export
Your portfolio data is yours. You can export it at any time, and if you leave, we return it and remove it on request rather than holding it hostage.
- Export available while your account is active
- Deletion on request after export
- No resale or sharing of your data
Questions from your insurer or IT?
We are happy to walk through our controls in detail before you move real data in.
Talk to us