Security and trust

Protection designed around buildings, people and accountable operations.

PropSync 360 combines payment-controlled access, organisation-level data separation, protected evidence and auditable workflows—while preserving the responsibilities of property management, the incumbent security agency and Wali Engineers.

Security principles

Verify identity and entitlement
Enforce access on the server
Minimise collected information
Protect evidence by default
Record material actions
Prepare for recovery

Controls in the current release

Security is enforced inside the workflow—not left to interface buttons.

The Phase 1 and Phase 2 release includes the following application and data controls.

01

Payment-gated activation

PropSync creates only a pending billing record before checkout. The organisation, first property and administrator account are created only after the payment status is independently verified.

02

Server-enforced tenant scope

Operational routes derive the organisation from the authenticated server session. Client-supplied organisation identifiers are not trusted for authorisation.

03

Protected user sessions

Session tokens use cryptographically secure random values, are stored as hashes and are delivered through Secure, HttpOnly, SameSite cookies.

04

Strong password derivation

Administrator passwords are processed using salted PBKDF2 with a high iteration count. Plain-text passwords are never stored.

05

Private evidence storage

Documents and images are stored separately from structured records. Every retrieval checks the requesting user’s organisation before returning content.

06

Signed billing events

Stripe webhook signatures are verified before subscription events are processed. Cancelled, unpaid or expired subscriptions suspend workspace access.

07

Origin and browser controls

State-changing browser requests enforce same-origin checks, while response headers limit framing, content execution and unnecessary device permissions.

08

Accountable audit events

Important workspace, request and commercial actions create immutable-style activity records with actor, organisation, entity and timestamp context.

Three-party security model

Coordination does not blur operational authority.

A property-security event may cross three organisations. PropSync makes the handover visible while keeping roles, source systems and approval rights distinct.

01

Property-management authority

Property management controls service priorities, commercial approvals, stakeholder communications and closure acceptance. It does not need operational control of the agency's guard-force tools.

02

Incumbent-agency boundary

The security agency keeps responsibility for licensed security operations, guard deployment, first response and its own SOPs. PropSync records only the handover and agreed event context.

03

Wali engineering scope

Wali Engineers receives the technical work context needed to diagnose, rectify and evidence issues such as CCTV, access control, barriers, sensors and networks.

04

Need-to-know evidence

Shared event records should expose only the evidence needed for the next accountable action. Video systems and detailed guard records remain in the authoritative agency or VMS environment unless a client-approved integration says otherwise.

Privacy and data protection by scope.

PropSync is designed to support responsible handling of property-management information under Singapore’s PDPA obligations without collecting data the workflow does not need.

Purpose-limited records

Collect operational information needed to assess, assign, complete and evidence property work. Avoid sensitive information that is unrelated to the task.

Controlled access and export

Restrict operational records to authorised users and log high-impact actions. Data exports remain subject to the client’s internal approval and retention rules.

Retention governance

Define retention by record category—such as service requests, incident evidence, compliance documents and commercial approvals—then delete or archive accordingly.

Privacy-first operating boundary

Facial recognition, biometric access control and CCTV video storage are outside Phase 1 and 2. Security video and detailed guard records remain with the authorised source system unless an approved integration defines a narrower exchange.

Payment and subscription protection

Payment confirms entitlement before account creation.

Stripe-hosted checkout handles card collection while PropSync controls subscription state and workspace access.

Hosted checkout

Payment details are entered on Stripe’s checkout surface; PropSync does not store card numbers.

Restricted credentials

Stripe credentials are held as hosted secrets and should be limited to only the permissions the billing service requires.

Verified events

Webhook signatures are checked before subscription state changes are accepted.

Entitlement enforcement

Inactive, unpaid or cancelled subscriptions cannot sign in to the client workspace.

Production hardening programme

Controls scheduled before broad commercial rollout.

These controls strengthen privileged access, monitoring, recovery and release governance as PropSync moves from controlled pilot to production scale.

Managed identity and MFA

Introduce a managed identity provider and require strong multi-factor authentication for Wali administrators and privileged client roles.

Security monitoring

Detect suspicious sign-in patterns, repeated authentication failures and abnormal administrative activity with defined escalation procedures.

Backup and restore

Schedule protected backups, verify restoration procedures and retain evidence that operational data can be recovered within the target window.

Incident response

Maintain breach, credential, availability and vendor-incident runbooks with named owners, communication paths and post-incident review.

Release protection

Add dependency review, secret scanning, vulnerability assessment and controlled promotion between development, staging and production.

Access governance

Review privileged access periodically, remove leavers promptly and require approval for high-impact roles and data exports.

Resilience targets

Availability matters because property operations do not pause.

Pilot targets create measurable expectations for recovery, vulnerability management and service continuity.

99.5%

Pilot availability target

Measured monthly, excluding agreed maintenance windows.

≤24h

Recovery point objective

Maximum targeted operational-data loss after a qualifying disruption.

8h

Recovery time objective

Targeted restoration window for the pilot service after a major outage.

Launch quality gate

No unresolved critical security vulnerability should remain at commercial launch. Recovery procedures and security-response ownership must be documented and exercised.

Shared responsibility

Technology controls work only when operating responsibilities are clear.

Wali Engineers protects the platform while each client remains accountable for authorised users, devices and appropriate business use.

Property management

Authorised users, escalation contacts, approval limits, stakeholder communication and the appropriate use of operational records.

Incumbent security agency

Licensed security operations, guard deployment, security SOPs, first response, agency-held security records and the integrity of agency-managed integrations.

Wali Engineers

Platform hosting, tenant controls, application security, technical integrations, engineering response records, vulnerability management and operational incident response.

End users and vendors

Password confidentiality, secure devices, accurate records, prompt reporting of suspicious activity and compliance with agreed operating procedures.

Review the platform with your operations and governance teams.

Use the product tour to assess workflows, roles, evidence requirements and subscription fit before onboarding a pilot property.

Open product tour