Security & Trust
Your data is yours — we protect it like it
Your property documents hold personal details about you, your tenants, and other parties. Here's how we keep that information safe, in plain language. The legal version of these commitments lives in our privacy policy and terms of service.
Encrypted end to end
Your data is encrypted while it travels to us and while it sits at rest — so it stays unreadable to anyone who shouldn't see it.
Isolated to your account
Every document and piece of prepared work is tied to your account and checked on every request. One customer can never see another customer's data.
AI that only sees your data
When Proppi prepares work, the assistant is restricted to files you have access to — and it can't invent or cite a document that isn't yours.
You stay in control
Export your originals anytime, delete documents whenever you like, or contact us to delete your whole account — and rest easy: we never sell your data or show advertising.
Private from our team
Our staff don't read your documents in normal operations. Where support genuinely needs access, it's with your consent and on the record.
Continuously checked
Every change we ship is automatically scanned for security issues and leaked credentials, and we keep our software current as risks emerge.
Encryption
- In transit. Everything that moves between your browser and our service is protected in transit, so it can't be read or tampered with along the way.
- At rest. Documents, database records, and backups are encrypted while stored.
- Sensitive credentials. The most sensitive secrets — like the keys that protect multi-factor authentication and account recovery — get an additional layer of encryption with keys that rotate over time.
- Passwords. Passwords are stored as salted one-way hashes — we never store, see, or transmit them in plain text.
Access control
- Login required, always. Every document and every piece of prepared work lives behind an account login. Public links and unauthenticated access to user data are not part of the product.
- You decide who sees what. When you invite someone to a property or portfolio, you choose whether they're an owner, editor, or viewer — and each role grants only the permissions it needs.
- Multi-factor authentication. MFA is available on every account, and required for our own team's internal systems. We strongly recommend enabling it on your account.
- Internal access is the exception. Our staff don't access your documents in the course of normal operations. Where access is needed for technical support, we do so with your consent or where required by law, and we keep an audit record.
How AI handles your data
Proppi uses AI to read, organise, and prepare source-linked work from your documents. The same commitments apply no matter which AI services sit behind the scenes:
- Only ever your own documents. When the assistant retrieves sources or prepares work, it's restricted to data you personally have access to. It can't reach into anyone else's files.
- No training on your content. Our AI providers are contractually prohibited from using your documents or questions to train their models.
- No long-term retention. AI providers process a request and return a result — they don't keep your content as a separate stored copy.
- No fabricated sources. When the assistant cites a document, our service first confirms that document really belongs to your account before it's shown. The model can't manufacture access to files you never uploaded.
- You confirm anything destructive. Actions like deleting or renaming a document always require your explicit confirmation — the assistant never does them on its own.
Your data, your control
- Export. You can download your original uploaded documents at any time from inside the app.
- Delete. You can delete individual documents at any time, or contact us to delete your entire account. Deletion is handled deliberately, so removed data doesn't linger in hidden places.
- No sale, no advertising. We do not sell your personal information and we do not show third-party advertising.
The companies that help us run Proppi
We rely on a small set of trusted providers to operate the service. We refine that set as technology and our needs evolve, so the current list — including the countries in which they operate — is kept in a separately maintained register rather than hard-coded into this page. Request the current list anytime by emailing privacy@proppi.ai.
Every provider is bound by an agreement that requires standards consistent with the New Zealand Privacy Act 2020 and the Australian Privacy Principles.
Responsible disclosure
If you believe you've found a security vulnerability in Proppi, we appreciate a quiet heads-up so we can fix it before it's exploited.
- Email security@proppi.ai with a description of the issue, the steps to reproduce, and any proof-of-concept material.
- Please give us a reasonable window to investigate and remediate before any public disclosure.
- Don't access, modify, or delete data that doesn't belong to your own account, and don't run automated scanners against the production service.
- We don't currently run a paid bug-bounty programme, but we'll acknowledge your report, keep you updated, and credit you in our release notes if you'd like.
Worried about your account?
If you think your Proppi account has been accessed without your permission — for example, you spot a login you don't recognise — change your password, enable multi-factor authentication, and email security@proppi.ai. We'll help you investigate and lock the account down.
This page describes the security measures we apply to the service in plain language. It isn't a substitute for the privacy policy (the legal framework for how we handle personal information) or the terms of service. Where the wording differs, those documents govern. Security questions and vendor-due-diligence requests are welcome at security@proppi.ai.
Start with the property in front of you.
Drop in the documents you already have — the first piece of work comes back cited, waiting on your approval.