Six pillars, on every deployment.
Every builder, every project, and every resident gets the same protection.
Multi tenant isolation
Each builder runs inside a fully isolated tenant. Every database query is scoped to it, so one builder can never read another builder’s data.
Encryption at rest
All stored data is encrypted with AES 256 on every database and storage volume.
Encryption in transit
Every connection between the apps, the portal, and the servers uses TLS 1.3.
Role based access
Every user holds one role with a bounded permission set. Every action is checked against role and scope before it runs.
Full audit logging
Every significant action is logged with who did it, what they did, and when. Logins, approvals, billing events, and admin changes are all on the record.
India data residency
Data is hosted in India, aligned with the Digital Personal Data Protection Act, 2023.
Every role has a boundary.
Each user holds one role with a defined scope. What they can see and do stops where that scope ends.
| Role | Scope | What the role covers |
|---|---|---|
| Super Admin | Platform wide | Tenant provisioning, feature flags, platform settings, audit log oversight |
| Builder Admin | Own builder organisation | Property setup, branding, member management, banner campaigns, analytics. No access to society maintenance. |
| Chairman / Secretary | Own society | Member approvals, notices, polls, events, amenity management, maintenance billing |
| Treasurer | Own society finances | Maintenance bills, collections, payment records, collection summaries |
| Committee Member | Own society | Management tools without the authority to change who sits on the committee |
| Estate Manager | Own society operations | Daily facility operations, work order oversight, staff and vendor coordination |
| Security Guard | Own gate | Visitor entry and exit logging, QR and OTP validation, worker check in and out |
| Concierge Staff | Assigned requests | Handle resident help requests and update their status |
| Commercial Owner | Own commercial unit | Unit access management, visitor approvals, notices |
| Resident / Family Member | Own household unit | Visitor approvals, dues payment, amenity booking, community features |
The data belongs to the builder, not REOSLABS.
REOSLABS earns through licensing, not through community data.
The builder owns the data
Resident, unit, and operational data belongs to the builder’s tenant. Export and migration are available on request.
No advertising, no data resale
No third party ad network runs in the app. Community data is never sold, shared, or monetised.
Resident consent at onboarding
Every resident agrees to a clear data policy when they join. Visibility, withdrawal, and deletion rights are honoured per that policy.
The right to leave
Builders can take a full data export in standard formats and move off the platform without retention penalties.
Talk to us about your security requirements.
We can walk through the architecture, audit trail, and data handling with your security and compliance leads.