Security
Built with the controls a growing operation needs.
Every capability on this page is real and already shipped — audited against the platform's own authorization, storage, and audit-logging architecture.
Access & identity
Role-based access
Seven built-in roles with a real permission-key system — never a single admin toggle.
Property-scoped access
Staff access can be scoped to specific properties, not just the whole organization.
Secure authentication
Argon2id password hashing, session revocation, and lockout on repeated failed logins.
Isolation & boundaries
Organization isolation
Every company's data lives in its own scoped workspace, enforced at every query.
Resident/contractor separation
Residents and contractors get their own dedicated, branded logins — separate from staff.
Contractor portal scope
Contractors see only the work orders assigned to them, never the wider portfolio.
Data protection & storage
Private file delivery
Documents and media are served through short-lived, permission-checked access, not public URLs.
S3-compatible private storage
Files are stored in private, S3-compatible object storage — never a public bucket.
Document visibility controls
Every property document carries an explicit resident-visibility setting.
Audit trail & AI boundary
Security audit logging
Authentication and security-relevant events are recorded with a correlation ID.
Business audit trail
Day-to-day changes across the platform are recorded in a structured AuditEvent trail.
AI permission boundary
Ask Pearly calls only permission-checked, read-only application functions — never raw queries.
A note on certifications
Pearly Gates does not currently hold SOC 2, ISO 27001, or PCI DSS certification, and this page makes no claim that it does. The controls described above reflect what is actually implemented in the product today.
Questions about how we protect your data?
Create your company workspace and see the access controls for yourself.
