Home / Security and trust

Built so one company's data never shows up in another's.

This page lists the controls that exist in the product today, in plain language. It makes no certification claims. If you need something we do not list, ask us and we will tell you straight.

What exists today

Who can see what

Company isolation
Each management company's data is isolated from every other company's. Each company has its own Hoamly subdomain.
Association scoping
Staff see only the associations they are assigned to. Board members are added per association and see only the association they are assigned to.
Roles
Four roles in the management app: Admin, Community Manager, Accountant and Board Member. Renters get a limited portal view: maintenance requests, announcements and documents.
Sign-in
Handled by Auth0 with email and password. Each company signs in on its own subdomain.

Money

Card and bank data
Card details are handled by Stripe. Pay-by-email links open Stripe Checkout. Bank connections run through Plaid. Payments are paid into the association's own connected account.
Approval before money moves
Invoices are approved before a Stripe payout. Collection notices above a reminder wait for a manager. Bank reconciliation matches are confirmed or rejected by staff.

Hoamly's own access

Support console
Hoamly staff use a separate console with its own sign-in. It is read-only by default. Elevated "break-glass" access is time-limited, sensitive actions need a second person's approval, and inspect sessions are audited.
Operational controls
Feature flags and kill switches per module, an incident banner shown to customers during an incident, and the ability to deactivate or sign out a user across companies.

Records and AI

Records you can audit
Collections keep an audit trail of every notice and approval. Every community vote produces an audit report. The general ledger opens the source document behind each line.
AI stays in its lane
AI drafts; your team approves. Document answers cite their sources. Staff Ask AI confirms before it acts.

What we do not claim

Hoamly does not currently hold a SOC 2, SOC 3, ISO 27001 or PCI DSS attestation of its own, and we do not describe the product as certified or compliant with NACHA, Regulation E, the FDCPA or WCAG 2.1 AA. Two-factor sign-in and single sign-on with your own identity provider are not available today. We would rather you hear that from this page than in a security questionnaire.

If your due-diligence process needs a written security summary, we provide a one-page overview of the controls above on request.

Ask a security question