Data & Privacy
Data Protection & Encryption
Your data is encrypted at rest with AES-256 via AWS storage-layer encryption, and in transit with TLS 1.2+.
AES-256 Encryption at Rest
Data stored in our databases and object storage is encrypted at rest with AES-256 through AWS storage-layer encryption (S3/RDS), a widely adopted industry-standard algorithm.
TLS 1.2+ in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.2+, protecting against interception and tampering.
Encrypted Automated Backups
Continuous encrypted backups with point-in-time recovery, stored on durable AWS storage across multiple availability zones.
Database Security
Managed database with encrypted connections and automatic security patches. Application-enforced per-company data isolation โ every query is scoped by company_id โ keeps each agency's data separate.
Data Residency & Sovereignty
Production data is hosted on AWS managed cloud infrastructure with documented data flows and encryption applied in transit and at rest.
Primary: AWS Cloud Infrastructure
Production data stored on AWS managed cloud infrastructure with documented data flows, encrypted at rest and in transit.
Encrypted Backups
Automated encrypted backups with point-in-time recovery, stored on durable AWS storage with documented data flows. Cross-border transfers governed by data processing agreements with sub-processors.
Sub-Processors
Limited use of sub-processors: Amazon Web Services (hosting, storage, and email via Amazon SES), Paddle (payments / Merchant of Record), Anthropic and Google (AI processing), Meta Platforms (WhatsApp Business messaging), Twilio (SMS), Cloudflare (DNS, CDN, WAF), and Sentry (error monitoring); Resend is used as email failover. All sub-processors are contractually bound to data protection requirements.
Privacy & Data Rights
We respect your privacy and your tenants' data rights under GDPR and UAE data-protection principles.
Data Minimization
We collect only data necessary for rental transactions. No third-party advertising or marketing trackers, and no third-party data sharing. Purpose-specific data collection.
Clear Retention Policies
Active deals: retained while active. Completed deals and supporting records: retained at least 5 years (Federal Decree-Law 50/2022, Article 29). Identity documents are minimised and deleted within 90 days of account termination. Data deleted on request after the applicable retention period.
Data Subject Rights
Full support for access requests, data portability (JSON/CSV export), correction, and deletion. We aim to respond within 30 days, in line with GDPR practice.
We Never Sell Your Data
Your data is never sold, rented, or shared with third parties for marketing. No third-party advertising or marketing trackers, no data monetization.
Infrastructure & Application
Cloud Infrastructure Security
Built on AWS infrastructure with multiple layers of protection, AWS Shield Standard DDoS protection, and CloudWatch automated monitoring.
AWS Cloud Infrastructure
Production data stored on AWS managed cloud infrastructure. Encryption at rest and in transit applied across all data, with automated encrypted backups.
AWS-hosted reliability
AWS-hosted architecture with automated encrypted backups and point-in-time recovery. AWS CloudWatch automated monitoring, with incident response handled during Dubai business hours.
DDoS Protection (AWS Shield Standard)
Network-layer DDoS protection through AWS Shield Standard, automatically enabled across our AWS infrastructure to mitigate common volumetric and protocol attacks.
Rate Limiting & Abuse Protection
Per-client rate limiting and request throttling protect against brute-force, scraping, and abuse, with automated alerting on anomalous traffic patterns.
Application Security
Secure by design with multiple layers of protection against common web vulnerabilities.
OWASP Top 10 Protection
Protected against all OWASP Top 10 vulnerabilities: SQL injection, XSS, CSRF, broken authentication, security misconfiguration, and more.
API Security
Token-based authentication, rate limiting, IP allowlisting (Enterprise), webhook signature verification, and API key rotation policies.
Input Validation & Sanitization
All user inputs validated and sanitized on both client and server. Built-in protection against injection attacks, with additional custom validators for Emirates ID, IBAN, and UAE-specific formats.
Dependency Scanning
Automated vulnerability scanning of all dependencies with modern scanning tools. Critical security patches prioritized for rapid deployment.
Access Control & Authentication
Enterprise-grade access management with role-based permissions, two-factor authentication, and comprehensive audit logging.
Role-Based Access Control (RBAC)
Granular permissions with 5 predefined roles (Admin, Manager, Team Lead, Agent, Property Administrator). Each role has precisely defined access levels with automatic company-level isolation.
Two-Factor Authentication (2FA)
Optional 2FA with TOTP-compatible authenticator apps and backup codes. Protect your account with an additional layer of security.
Enterprise SSO
Single Sign-On via SAML 2.0 (Okta, Azure AD, and other identity providers) available on the Enterprise tier. Simplify access management across your organization.
Secure Session Management
Secure token-based authentication with short-lived access tokens and automatic refresh. Sessions can be revoked at any time.
Compliance & Operations
UAE Regulatory Compliance
Purpose-built for UAE real estate regulations across 7 emirates โ RERA, DLD, Ejari, Tawtheeq, and registration workflows (rule-based compliance, not API integration).
RERA Compliance
Compliance rule tracking for UAE real estate regulations โ deep coverage for Dubai (RERA/DLD), Abu Dhabi (ADREC), and Sharjah Municipality, plus rule tracking for the Northern Emirates.
DLD-Aligned Workflows
Workflows aligned with Dubai Land Department processes and document standards. TenancyDesk prepares submissions; it does not connect directly to government portal APIs.
Data Protection by Design
Encryption at rest (AES-256) and in transit (TLS 1.2+), least-privilege access controls, audit logging on critical actions. Built on GDPR-aware infrastructure providers (AWS, Paddle, Anthropic, Google, Meta, Twilio, Cloudflare, Sentry).
Privacy by Design
Personal data is handled on data-protection-by-design principles โ encryption, least-privilege access controls, and audit logging applied across all personal-data processing, with consent and retention controls built in.
Data Residency & Transfers
Production data is hosted on AWS managed cloud infrastructure with documented data flows. Cross-border transfers are governed by data processing agreements with all sub-processors, with encryption applied in transit and at rest.
Registration Compliance
Submission-prep workflows for UAE registration systems โ Ejari, Tawtheeq, Tasdeeq, EJAAR (output is a packaged file, not an API call).
Security Operations & Monitoring
AWS CloudWatch monitoring with automated alerting, documented incident-response runbooks, and continuous automated security checks.
AWS CloudWatch Monitoring
Continuous monitoring of system access, API calls, and suspicious activities. Automated alerts for security events with documented incident response procedures.
Comprehensive Audit Logging
Every action logged with timestamp, user ID, IP address, and action details. Retention aligned with UAE legal requirements for real estate records. Exportable for compliance audits.
Incident Response Plan
Documented incident-response runbooks. Security events are triaged, escalated, and logged, with breach notifications aligned to applicable data-protection requirements.
Security Testing & Monitoring
Continuous automated dependency and vulnerability scanning, infrastructure monitoring through AWS CloudWatch, and OWASP-aligned application security reviews. Critical vulnerabilities are prioritized for rapid patching.
Automatic Security Updates
Frameworks and dependencies kept current with security patches. Automated dependency scanning with prompt patching of known vulnerabilities.
Application Hardening
Defense-in-depth at the application layer: parameterized database queries (SQL-injection-safe), output encoding (XSS), CSRF protection, strict server-side input validation, and per-client rate limiting โ covering the OWASP Top 10.
Security Certifications & Compliance
Our security posture combines industry-standard infrastructure, established best practices, and UAE-specific compliance.
Current Status
- AWS Well-Architected design principles (self-assessed)
- Data-protection-by-design controls (encryption, access control, audit logging)
- GDPR-aware infrastructure (AWS, GDPR-compliant sub-processors)
- PCI DSS Level 1 (via Paddle, our Merchant of Record)
- Hosted on AWS (SOC 2 Type II); TenancyDesk itself is not separately SOC 2 certified
Security Practices
- Continuous dependency and vulnerability scanning
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Least-privilege access with full audit logging
- Automated infrastructure monitoring and alerting
People
Employee & Organizational Security
Access to customer data is tightly controlled, logged, and governed by confidentiality agreements.
Vetted Access
Anyone granted access to production data is vetted and bound by confidentiality obligations before access is provisioned.
Secure Development
Security-by-design development with code review, automated dependency scanning, and least-privilege deployment access. Secrets are managed via environment configuration, never committed to source.
Need-to-Know Access
Access to customer data is restricted to specific troubleshooting needs, logged, and revocable at any time.
Confidentiality Agreements
Everyone with access to customer data is bound by confidentiality agreements.
Security FAQs
Common security questions from enterprise customers.
Ready to See How We Protect Your Data?
Put your agency's most sensitive rental data on infrastructure built for security and transparency. Start your 14-day free trial with full security features included.