Skip to content

Section 5

How your data is secured

Describe only controls that are actually implemented. Each item below is marked with its real status so nothing here overstates the current build.

Encryption in transit
All traffic served over HTTPS/TLS. Webhook payloads from Meta are verified by HMAC-SHA256 signature against the raw request body, using a constant-time comparison.Implemented
Encryption at rest
Database and file storage encrypted at rest by the hosting provider. Confirm with provider before publishing
Tenant isolation
Every record is scoped to an organization and enforced at the database layer with row-level security, so one organization's listings, photos, and conversations cannot be read by another. Verified against a live database with two separate accounts in separate organizations: the cross-account read returned nothing, and a direct attempt to read another organization's data was denied by the database itself, not merely filtered by the application.Implemented
Access control
Access to production data is limited to the owner of the business, protected by multi-factor authentication, and logged. Confirm MFA is enabled
Secrets
Platform tokens and API keys are stored as environment secrets, never in the codebase or the repository.Implemented
Retention
Conversation records are retained for 24 months, then deleted or anonymised. Listing data is retained while your account is active, and deleted 30 days after account closure.
Sub-processors
We use third parties for hosting, database, AI model inference, and email delivery. The current list is published at /legal/sub-processors and we will give notice before adding one.
Breach response
If a personal data breach occurs that meets the notification threshold, we will notify the National Privacy Commission and affected individuals within 72 hours of knowledge of the breach, as required by the DPA and its IRR.
Payment data
We do not store card numbers. Billing for early access is invoiced manually (GCash/bank transfer) — no automated payment provider is integrated yet, so no card or account data passes through PropAI PH at all in this build.

What we ask of you

  • Use a strong, unique password and enable two-factor authentication on your Facebook Page.
  • Do not enter a buyer's identity documents, financial account numbers, or government IDs into listing fields — the service is not designed to hold sensitive personal information.
  • Tell us promptly if you suspect your account has been accessed by someone else.

Reporting a security issue

If you believe you've found a security vulnerability, email security@propaiph.com. We will acknowledge within 2 business days and will not pursue good-faith researchers who follow responsible disclosure.