Trust
Where your tenants’ data lives.
You are handing us the names, addresses and signed agreements of people renting your apartments. This page is what we’d want to read before doing that.
One organisation cannot see another
Tenancy is enforced at the data layer, on every query, not by a filter someone remembered to add in the UI. An organisation slug that is not yours returns a 404 rather than a permission error, so the existence of other operators does not leak either.
Documents are not public URLs
Leases, signature images and assistant attachments are never servable by link. What may be served to anyone is defined in exactly one place and enforced in three that cannot disagree: the file route, the URL builder and the storage driver each refuse independently.
Everything is attributed
Who changed what, and when, kept as an audit trail you can read. The email log, which records every automated message, is never pruned, because “did we send that?” is a question that gets asked about last year.
Export always works
Reservations, contracts and the signing evidence, out to a file, whenever you want. Your data stays exportable for 90 days after an account closes.
GDPR
You are the controller. We are the processor.
Your tenants’ personal data is yours. We process it on your instructions and for no other purpose. We do not sell it, we do not mine it, and we do not use it to train anything.
That relationship is written down in a data processing agreement you can read before you sign anything, and the third parties involved are named on the sub-processors page. A new one gets added to that page before it goes into production, not after.
Being straight with you
What we do not have yet
No SOC 2, no ISO 27001, no penetration test report to send you. Those are real and we have not done them. If your procurement process requires one, we are not yet a company you can buy from, and it is better that you know that on this page than after four meetings.
What we do have is a small, readable system with the isolation and audit properties above, run by the people who wrote it. Ask us anything specific at security@thequarter.ai and you will get a straight answer rather than a certificate.
Reporting a vulnerability
We will not send lawyers.
Write to security@thequarter.ai with what you found and how to reproduce it. We aim to acknowledge within two working days and to fix anything serious before we do anything else. Test against your own trial account, do not touch other people’s data, and we have no complaint with you.
See it against your own portfolio
Thirty minutes, your units, your contracts. If it is not a fit we’ll say so. We’d rather lose the trial than the reputation.
30 days free · no card required · cancel by closing the tab