Security & trust

Your homeowners' money and records, treated like the deed.

An association hands its software the operating account, the reserve fund, every owner's contact details, and the minutes that decide a lien. Here is exactly how we protect that — and what we will not claim until it is true.

How it's built

Six controls, stated plainly.

No badge wall, no certifications we don't hold. If a control is in progress we say in progress, and we will show you the evidence on a call.

SOC 2 Type II — audit in progress

Controls are monitored continuously with Vanta while the Type II observation window runs. We will publish the report under NDA the day it is issued; until then we will show you the live control dashboard on a call rather than imply we are already certified.

Row-level tenant isolation

Every query — every report, every export, every AI retrieval — is scoped to your association through Postgres row-level security. Your residents never appear in another community's data, by construction rather than by convention.

Encrypted in transit and at rest

TLS on every connection and 256-bit encryption at rest across the database, document vault, call recordings, and backups.

Card data never touches us

Payments run on Stripe's PCI-DSS infrastructure. We store payment tokens and reconciliation references — never card numbers. Bank links are established through Plaid or Stripe Financial Connections.

Secure development by default

Static analysis, dependency and credential scanning, and row-level-security validation run on every commit. Production access is role-scoped and logged.

Audit logs that don't disappear

Who changed a ledger entry, who approved a violation notice, who exported the roster — recorded, timestamped, and visible to the board. Boards turn over; the record shouldn't.

Privacy

What we do with your data — and what we never do.

Your data is yours

The ledger, roster, documents, transcripts, and recordings belong to the association. Export them at any time in formats a CPA or a court can read — no exit fee, no permission required.

We don't train on your community

Milo sees only what your board has put into SMPLR: governing documents, ledger, minutes, vendors, roster. None of it is used to train any underlying model, and calls to frontier model APIs go out under zero-retention terms.

We don't sell resident data

Not to advertisers, not to data brokers, not to vendors looking for leads. Homeowner contact details exist to run the association, full stop.

Access follows the role

Board members, committee members, managers, and homeowners each see a different slice. Roles change the moment a term ends, and every access change is logged.

The binding versions live in our Privacy Policy, Terms of Service, and Master Service Agreement. Where this page and those documents differ, those documents govern.

Availability & recovery

Uptime you can check without asking us.

Every service — the app, payments, mail, email and SMS, Milo, bank sync, and the API — reports to a public status page. Incidents are posted there and written up in the changelog with our name on them.

  • Continuous backups with point-in-time recovery of the association database
  • Two-factor authentication available on every account, enforceable board-wide
  • Approval gates on outbound money — a check leaves only after a human approves it
  • Positive Pay files sent to your bank the moment a printed check ships
  • Exportable records for auditors, insurers, and successor boards
Responsible disclosure

Found something? Tell us first.

Email security@madesmplr.com with steps to reproduce. We acknowledge reports within one business day, keep you updated while we fix, and credit researchers who want the credit.

  • Test only against accounts you own or have written permission to test
  • No denial-of-service, no social engineering of our team or our customers
  • Don't access, modify, or retain another association's data — tell us instead and stop
  • Give us a reasonable window to fix before publishing, and we won't pursue you for good-faith research

Completing a vendor security questionnaire for your board, insurer, or management company? Send it to security@madesmplr.com and we will return it, filled in, usually within two business days.

Start with one community. Or all forty.

Free for thirty days. No card required.

For management companies with 500+ doors, ask about Multi-Portfolio onboarding.