Trust & Safety

Security & Compliance

How PropertyOS protects your data today — only measures that are actually in place are listed here.

Security Measures

Multiple layers of protection to keep your data safe.

Data in Transit

Traffic is served over HTTPS only

  • HTTPS enforced with HSTS (one year, preload)
  • Secrets kept in environment configuration, never in the browser bundle
  • Scoring requests are made server-side; the browser never talks to the model service

Infrastructure

EU hosting with platform-level protection

  • Scoring service on Hetzner in Finland (EU)
  • Managed PostgreSQL in the EU
  • Vercel platform DDoS mitigation in front of the web app

Access Control

Authentication and authorization on every protected route

  • Sign-in and sessions handled by Clerk
  • Role-based access: monitoring and admin tools are admin-only
  • Every API route checks its own access rules and is rate limited per client

Application Security

Defensive defaults in the application

  • Strict Content-Security-Policy and security headers on every response
  • All API input validated against published schemas
  • Internal error details are never returned in production responses
  • New dependency releases are held for a day before they can be installed

Compliance

PropertyOS holds no third-party security certification yet; we will list them here once audited.

GDPR

EU data residency

Data is stored and processed in the EU. Contact details are used only to answer the message sent.

Data provenance

Official sources

Economic data comes from official ECB and Eurostat releases, with provenance kept per dataset.

Data Residency

Your data is stored and processed within the European Union.

🇫🇮

Primary

Hetzner Helsinki (EU)

🇪🇺

Databases

CapyDB managed Postgres (EU)

🌍

CDN

Vercel Edge Network (Global)

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:

Security Reports: security@propertyos.eu

PGP Key: Available upon request

We commit to acknowledging your report within 24 hours and providing regular updates on our progress. We will not take legal action against researchers who follow responsible disclosure practices.

Need More Information?

Contact us for security questions, to report a vulnerability, or to discuss your compliance requirements.