How Occupella protects your data

What is in place today, stated as specifically as we can. We don’t hold a security certification such as SOC 2, and this page doesn’t claim one.

Your data stays in your company

Every query Occupella runs is scoped to your company. A test reads every query in the codebase to keep it that way, and another tries to read one company's data from another's session.

Credentials encrypted at rest

Your Buildium API keys are encrypted before they are stored, entered once and never shown again, not even to you.

Google access through managed sign-in

Gmail, Calendar and Drive connect through Composio's OAuth with the minimum scopes Occupella needs. We never see or store your Google password.

Disconnect deletes the copy

Disconnecting Buildium deletes Occupella's synced copy of your data, as Buildium's API terms require. There is no option to keep it.

Roles on the changes that can't be undone

A payment, a charge and closing a work order need a manager or an admin, and are refused if the role can't be verified.

No double charges

Each approved change takes a lock before the Buildium call. A change that might have half-landed is flagged for review and never retried automatically.

Identifiers kept off the screen

Buildium record numbers, tenant emails and phone numbers are stripped from replies as they are written.

Outside text can't give orders

A resident's message, an email, a file or a web page is fenced off before the AI reads it, so text written by someone else can't tell Occupella what to do.

Subprocessors

The service providers that process data for Occupella, and what each one does. The same list is in our privacy policy.

  • Anthropic: The AI models that read your data and write answers and drafts.
  • Voyage AI: Turns remembered facts into search vectors so they can be recalled later.
  • Supabase: Database and sign-in. Your synced Buildium data and your account live here.
  • Render: Runs the Occupella servers and background workers.
  • Vercel: Hosts this website and the Occupella web app.
  • Composio: Manages the Google sign-in (OAuth) for Gmail, Calendar and Drive.
  • Stripe: Billing and payments for your subscription.
  • Twilio: Text messages and calls, and the carrier registration for your business number.
  • Tavily: Web search, when a question needs public information.
  • Sentry: Error reports, so we can see and fix failures.
  • Langfuse: Traces of AI requests, so we can check answer quality.
  • PostHog: Product analytics on this website and in the app.
  • Apollo.io: Identifies which businesses visit this website. The marketing site only.
  • US Census geocoder: Turns property addresses into map coordinates. A public government service.
  • US government public data (FEMA, HUD, EPA, USFS): Flood, wildfire and radon data and fair market rents, looked up by property location.
  • Browserbase: Browser automation for websites without an API. Not in use for customers today.
  • E2B: An isolated sandbox for running analysis code. Not in use for customers today.

Agreements and reports

A data processing agreement is available on request. To ask for one, or to report a security problem, email team@occupella.com.

Questions before you connect Buildium?

Email team@occupella.com and a person will answer.