What is in place today, stated as specifically as we can. We don’t hold a security certification such as SOC 2, and this page doesn’t claim one.
Every query Occupella runs is scoped to your company. A test reads every query in the codebase to keep it that way, and another tries to read one company's data from another's session.
Your Buildium API keys are encrypted before they are stored, entered once and never shown again, not even to you.
Gmail, Calendar and Drive connect through Composio's OAuth with the minimum scopes Occupella needs. We never see or store your Google password.
Disconnecting Buildium deletes Occupella's synced copy of your data, as Buildium's API terms require. There is no option to keep it.
A payment, a charge and closing a work order need a manager or an admin, and are refused if the role can't be verified.
Each approved change takes a lock before the Buildium call. A change that might have half-landed is flagged for review and never retried automatically.
Buildium record numbers, tenant emails and phone numbers are stripped from replies as they are written.
A resident's message, an email, a file or a web page is fenced off before the AI reads it, so text written by someone else can't tell Occupella what to do.
The service providers that process data for Occupella, and what each one does. The same list is in our privacy policy.
A data processing agreement is available on request. To ask for one, or to report a security problem, email team@occupella.com.
Email team@occupella.com and a person will answer.