Home / Security and trust
Built so one company's data never shows up in another's.
This page lists the controls that exist in the product today, in plain language. It makes no certification claims. If you need something we do not list, ask us and we will tell you straight.
What exists today
Who can see what
- Company isolation
- Each management company's data is isolated from every other company's. Each company has its own Hoamly subdomain.
- Association scoping
- Staff see only the associations they are assigned to. Board members are added per association and see only the association they are assigned to.
- Roles
- Four roles in the management app: Admin, Community Manager, Accountant and Board Member. Renters get a limited portal view: maintenance requests, announcements and documents.
- Sign-in
- Handled by Auth0 with email and password. Each company signs in on its own subdomain.
Money
- Card and bank data
- Card details are handled by Stripe. Pay-by-email links open Stripe Checkout. Bank connections run through Plaid. Payments are paid into the association's own connected account.
- Approval before money moves
- Invoices are approved before a Stripe payout. Collection notices above a reminder wait for a manager. Bank reconciliation matches are confirmed or rejected by staff.
Hoamly's own access
- Support console
- Hoamly staff use a separate console with its own sign-in. It is read-only by default. Elevated "break-glass" access is time-limited, sensitive actions need a second person's approval, and inspect sessions are audited.
- Operational controls
- Feature flags and kill switches per module, an incident banner shown to customers during an incident, and the ability to deactivate or sign out a user across companies.
Records and AI
- Records you can audit
- Collections keep an audit trail of every notice and approval. Every community vote produces an audit report. The general ledger opens the source document behind each line.
- AI stays in its lane
- AI drafts; your team approves. Document answers cite their sources. Staff Ask AI confirms before it acts.
What we do not claim
Hoamly does not currently hold a SOC 2, SOC 3, ISO 27001 or PCI DSS attestation of its own, and we do not describe the product as certified or compliant with NACHA, Regulation E, the FDCPA or WCAG 2.1 AA. Two-factor sign-in and single sign-on with your own identity provider are not available today. We would rather you hear that from this page than in a security questionnaire.
If your due-diligence process needs a written security summary, we provide a one-page overview of the controls above on request.