eigrSign in
← Back to Security Center

Security practices

Security is built into the product rather than bolted on. Below is how access, data and operations are protected.

Authentication

Sign-in uses email and password or Google. Passwords are never stored in clear text, and sessions use short-lived tokens. On mobile the app can be locked with Face ID or a passcode.

Access control

All data is protected by row-level security in the database: you only see your own properties, and shared access is granted explicitly per property or project with a defined role. Administrative roles live in a separate role table and are verified server-side on every call.

Encryption

All traffic runs over TLS. Database, files and backups are encrypted at rest by our hosting provider.

Logging and traceability

Security-relevant events — role changes, access sharing, deletions and administrative changes — are written to an audit log. Access to properties and estate settlements is logged separately.

Backups

The database is backed up automatically by the hosting provider, with point-in-time recovery available.

Incident response

Suspected vulnerabilities or security incidents can be reported through the form in the Security Center or to our security address. We acknowledge receipt, investigate, and notify affected users and the supervisory authority where the law requires it.