Security
Post-handover data is sensitive: homes, families, payments, defects. Our trust posture is public because residents and developers both deserve to see it.
Access is earned, not assumed
Role-based access control with default-deny permissions. Sign-in is closed: there is no public registration, and a Google account that is not on the approved list is refused outright — no account is created and no session is issued. Where a limited read-only preview exists, it is shown synthetic demo data only, never real resident data.
Tenant and workspace isolation
Each developer's data lives inside its own workspace boundary, enforced server-side on every query.
AI with guardrails
AI output is always labeled as draft, separates facts from assumptions, and never finalizes sensitive decisions — payments, access permissions and warranty rulings are human-only. Live AI providers are disabled until explicitly approved by the platform owner.
Auditability
Sensitive actions produce audit events with actor, action and timestamp. Reviews and approvals carry named accountability.
Honest capability status
This build runs with live AI, online payments, external messaging and smart-building integrations disabled. We publish what is on and what is off — no simulated capabilities.