Section 5
How your data is secured
Describe only controls that are actually implemented. Each item below is marked with its real status so nothing here overstates the current build.
- Encryption in transit
- All traffic served over HTTPS/TLS. Webhook payloads from Meta are verified by HMAC-SHA256 signature against the raw request body, using a constant-time comparison.Implemented
- Encryption at rest
- Database and file storage encrypted at rest by the hosting provider. Confirm with provider before publishing
- Tenant isolation
- Every record is scoped to an organization and enforced at the database layer with row-level security, so one organization's listings, photos, and conversations cannot be read by another. Verified against a live database with two separate accounts in separate organizations: the cross-account read returned nothing, and a direct attempt to read another organization's data was denied by the database itself, not merely filtered by the application.Implemented
- Access control
- Access to production data is limited to the owner of the business, protected by multi-factor authentication, and logged. Confirm MFA is enabled
- Secrets
- Platform tokens and API keys are stored as environment secrets, never in the codebase or the repository.Implemented
- Retention
- Conversation records are retained for 24 months, then deleted or anonymised. Listing data is retained while your account is active, and deleted 30 days after account closure.
- Sub-processors
- We use third parties for hosting, database, AI model inference, and email delivery. The current list is published at /legal/sub-processors and we will give notice before adding one.
- Breach response
- If a personal data breach occurs that meets the notification threshold, we will notify the National Privacy Commission and affected individuals within 72 hours of knowledge of the breach, as required by the DPA and its IRR.
- Payment data
- We do not store card numbers. Billing for early access is invoiced manually (GCash/bank transfer) — no automated payment provider is integrated yet, so no card or account data passes through PropAI PH at all in this build.
What we ask of you
- Use a strong, unique password and enable two-factor authentication on your Facebook Page.
- Do not enter a buyer's identity documents, financial account numbers, or government IDs into listing fields — the service is not designed to hold sensitive personal information.
- Tell us promptly if you suspect your account has been accessed by someone else.
Reporting a security issue
If you believe you've found a security vulnerability, email security@propaiph.com. We will acknowledge within 2 business days and will not pursue good-faith researchers who follow responsible disclosure.