Security
We treat tenant data like it’s our own.
Encrypted end-to-end, auditable action by action, and built so a human always stays accountable.
A human always stays accountable.
Work orders need operator approval before a vendor is dispatched. Ambiguous calls route to the assigned property manager with full context.
Your tenant data never trains a foundation model.
Conversations, rent rolls, and work-order content are used for inference only — never sent to model providers for training or fine-tuning.
Every decision is auditable end-to-end.
Each tool call, classification, and outbound message is logged with timestamps, inputs, and outcomes. Exportable on request.
Access is scoped by default.
Role-based permissions for PMs, regional managers, and portfolio execs. Every action attributes to a named user on a named property.
Encrypted in transit and at rest.
TLS on every web, SMS, voice, and email connection. Tenant data and conversation history encrypted on managed cloud storage.
Aligned with SOC 2 controls.
Our program is modeled on SOC 2 control families. We do not claim certifications we have not earned — current status available on request.
How it actually works
Three controls doing most of the work.
- Inference
Tenant data flows through the model, not into it.
Requests hit the model provider under zero-retention terms and return without being persisted on their side for training.
- Guardrails
Compliance is enforced before the model answers.
TCPA keywords (STOP, START, HELP) are intercepted architecturally. Fair Housing is enforced in-prompt and validated by a post-generation classifier.
- Trail
Every Clara action writes an audit row.
Tool calls, approvals, escalations, and outbound messages persist with full context. SSO and IP allow-listing available for enterprise on request.
What’s in place
The boring list procurement asks for.
- Authentication
- Encryption in transit & at rest
- Secrets management
- Tenant data scoping
- Role-based access
- Immutable audit log
- Abuse & rate limits
- No model training
Enterprise ready
Enterprise-ready from day one
Integrates with your existing PMS. Scales with your portfolio. Deploys in days, not months. Every Clara interaction is TCPA compliant, Fair Housing aware, and fully auditable.
TCPA Compliant
Fair Housing Compliant
Complete Audit Trail
FAQ
What buyers, ask.
Running a vendor review? We’ll meet you there.
DPAs, subprocessor lists, questionnaire responses, and sub-processor change alerts — all in one place.
Direct line: security@propflowai.co