We implement what we can verify, and we label what is still in progress or planned. We do not claim certifications we have not earned.
We collect only what property management requires: contact details, property and unit information, maintenance requests, and payment records processed through a verified payment provider. We do not sell your data. Residents never see other residents' information. You can request export or deletion of your data at any time.
Data is encrypted in transit (TLS) and at rest in storage. Authentication uses secure password hashing with secure reset. Sessions expire and can be logged out. Access is role-based with least-privilege defaults. Secrets are stored in secure secret storage — never in client code, URLs, or logs.
AI operates only within the current user's permissions. AI never independently reveals private information, approves large expenses, sends legal notices, modifies executed leases, rejects applicants, makes Fair Housing-sensitive decisions, charges residents, transfers funds, files taxes, deletes important records, dispatches emergency services, gives hazardous repair instructions, presents estimates as confirmed facts, or presents simulated actions as completed. Important recommendations show: information reviewed, recommendation, reasoning, confidence, risks, required approval, and expected result.
Administrators configure allowed AI actions, approval requirements, spending limits, communication rules, emergency escalation, legal-document restrictions, financial restrictions, and vendor-dispatch restrictions. High-risk actions wait for human approval based on your rules. Every AI action creates an audit record.
Data is separated at the organization level. Property-level permissions restrict who sees each property's records. Sensitive fields are protected. Audit logs record important actions. Residents, technicians, owners, and staff each see only what their role permits.
Role templates (Company Owner, Portfolio Executive, Regional Manager, Property Manager, Assistant Manager, Maintenance Director, Maintenance Supervisor, Technician, Leasing Agent, Accountant, Office Staff, Vendor, Resident, Read-Only Investor) are being enforced at the database and server-action level — not only by hiding buttons. Custom roles are planned.
Each integration is shown with an honest status: Connected, Not Connected, Setup Required, Beta, Coming Soon, or Error. A connection is never shown as 'Connected' without verified authorization. No integrations are currently authorized.
A real-time service-status page and incident history are planned. For now, report incidents using the contact below.
You can request a data export or account deletion from your account settings. Account deletion removes your personal data in accordance with our Privacy Policy. Deletion is confirmed before it proceeds and is not reversible.
PropPilot AI aims for WCAG-aligned usability: screen-reader compatibility, keyboard navigation, visible focus indicators, adjustable text size, high-contrast mode, reduced-motion mode, and color-blind-safe status indicators (status is always shown as text, never color alone). Voice input is supported where available. We continue to improve accessibility based on user feedback.
Include safe technical details only — never passwords, payment info, or private messages.
Contact PropPilot SupportPropPilot AI does not claim "SOC 2 certified," "bank-level security," or "unhackable." Items marked Independently Verified will be updated only after third-party verification is complete.