Payment-gated activation
PropSync creates only a pending billing record before checkout. The organisation, first property and administrator account are created only after the payment status is independently verified.
PropSync 360 combines payment-controlled access, organisation-level data separation, protected evidence and auditable workflows—while preserving the responsibilities of property management, the incumbent security agency and Wali Engineers.
Controls in the current release
The Phase 1 and Phase 2 release includes the following application and data controls.
PropSync creates only a pending billing record before checkout. The organisation, first property and administrator account are created only after the payment status is independently verified.
Operational routes derive the organisation from the authenticated server session. Client-supplied organisation identifiers are not trusted for authorisation.
Session tokens use cryptographically secure random values, are stored as hashes and are delivered through Secure, HttpOnly, SameSite cookies.
Administrator passwords are processed using salted PBKDF2 with a high iteration count. Plain-text passwords are never stored.
Documents and images are stored separately from structured records. Every retrieval checks the requesting user’s organisation before returning content.
Stripe webhook signatures are verified before subscription events are processed. Cancelled, unpaid or expired subscriptions suspend workspace access.
State-changing browser requests enforce same-origin checks, while response headers limit framing, content execution and unnecessary device permissions.
Important workspace, request and commercial actions create immutable-style activity records with actor, organisation, entity and timestamp context.
Three-party security model
A property-security event may cross three organisations. PropSync makes the handover visible while keeping roles, source systems and approval rights distinct.
Property management controls service priorities, commercial approvals, stakeholder communications and closure acceptance. It does not need operational control of the agency's guard-force tools.
The security agency keeps responsibility for licensed security operations, guard deployment, first response and its own SOPs. PropSync records only the handover and agreed event context.
Wali Engineers receives the technical work context needed to diagnose, rectify and evidence issues such as CCTV, access control, barriers, sensors and networks.
Shared event records should expose only the evidence needed for the next accountable action. Video systems and detailed guard records remain in the authoritative agency or VMS environment unless a client-approved integration says otherwise.
PropSync is designed to support responsible handling of property-management information under Singapore’s PDPA obligations without collecting data the workflow does not need.
Collect operational information needed to assess, assign, complete and evidence property work. Avoid sensitive information that is unrelated to the task.
Restrict operational records to authorised users and log high-impact actions. Data exports remain subject to the client’s internal approval and retention rules.
Define retention by record category—such as service requests, incident evidence, compliance documents and commercial approvals—then delete or archive accordingly.
Facial recognition, biometric access control and CCTV video storage are outside Phase 1 and 2. Security video and detailed guard records remain with the authorised source system unless an approved integration defines a narrower exchange.
Payment and subscription protection
Stripe-hosted checkout handles card collection while PropSync controls subscription state and workspace access.
Payment details are entered on Stripe’s checkout surface; PropSync does not store card numbers.
Stripe credentials are held as hosted secrets and should be limited to only the permissions the billing service requires.
Webhook signatures are checked before subscription state changes are accepted.
Inactive, unpaid or cancelled subscriptions cannot sign in to the client workspace.
Production hardening programme
These controls strengthen privileged access, monitoring, recovery and release governance as PropSync moves from controlled pilot to production scale.
Introduce a managed identity provider and require strong multi-factor authentication for Wali administrators and privileged client roles.
Detect suspicious sign-in patterns, repeated authentication failures and abnormal administrative activity with defined escalation procedures.
Schedule protected backups, verify restoration procedures and retain evidence that operational data can be recovered within the target window.
Maintain breach, credential, availability and vendor-incident runbooks with named owners, communication paths and post-incident review.
Add dependency review, secret scanning, vulnerability assessment and controlled promotion between development, staging and production.
Review privileged access periodically, remove leavers promptly and require approval for high-impact roles and data exports.
Resilience targets
Pilot targets create measurable expectations for recovery, vulnerability management and service continuity.
99.5%
Measured monthly, excluding agreed maintenance windows.
≤24h
Maximum targeted operational-data loss after a qualifying disruption.
8h
Targeted restoration window for the pilot service after a major outage.
Launch quality gate
No unresolved critical security vulnerability should remain at commercial launch. Recovery procedures and security-response ownership must be documented and exercised.
Shared responsibility
Wali Engineers protects the platform while each client remains accountable for authorised users, devices and appropriate business use.
Property management
Authorised users, escalation contacts, approval limits, stakeholder communication and the appropriate use of operational records.
Incumbent security agency
Licensed security operations, guard deployment, security SOPs, first response, agency-held security records and the integrity of agency-managed integrations.
Wali Engineers
Platform hosting, tenant controls, application security, technical integrations, engineering response records, vulnerability management and operational incident response.
End users and vendors
Password confidentiality, secure devices, accurate records, prompt reporting of suspicious activity and compliance with agreed operating procedures.
Use the product tour to assess workflows, roles, evidence requirements and subscription fit before onboarding a pilot property.