Security at PropFlow

We take the security of your data seriously. Learn about the measures we implement to keep your information safe and secure.

Security Features

Data Encryption

All data is encrypted both in transit (TLS 1.3) and at rest (AES-256). Your sensitive information is never stored in plain text.

Two-Factor Authentication

Add an extra layer of security to your account with SMS-based or app-based two-factor authentication.

Secure Authentication

We use industry-standard authentication protocols with secure session management and automatic timeout for inactive sessions.

Access Controls

Role-based access control ensures that users only see and access the data they need. Staff permissions can be customized per user.

Secure Infrastructure

Our infrastructure is hosted on enterprise-grade cloud platforms with DDoS protection, firewalls, and continuous monitoring.

Regular Backups

Your data is automatically backed up daily with point-in-time recovery capabilities. Backups are encrypted and stored securely.

Our Security Commitment

At PropFlow, security is not an afterthought—it's built into everything we do. We understand that you trust us with sensitive property and financial data, and we take that responsibility seriously.

Our security program is designed to protect your data throughout its lifecycle, from the moment it enters our system to when it's securely deleted. We continuously monitor for threats and regularly update our security measures to address new challenges.

SOC 2 Aligned
GDPR Ready
Kenya DPA Compliant

Security Practices

Vulnerability Management

We conduct regular security assessments and penetration testing to identify and address potential vulnerabilities before they can be exploited.

Incident Response

We have a dedicated incident response team and established procedures to quickly detect, respond to, and recover from security incidents.

Employee Security

All employees undergo security training and background checks. Access to production systems is strictly controlled and audited.

Compliance

We comply with Kenyan data protection laws and implement best practices aligned with international standards like ISO 27001.

Payment Security

All payment transactions through M-Pesa are processed securely using Safaricom's official Daraja API. We never store complete M-Pesa credentials or sensitive payment data.

  • PCI-DSS aligned payment processing
  • End-to-end encrypted transactions
  • Real-time fraud monitoring
  • Automatic receipt generation

M-Pesa Secure Payments

Report a Security Issue

We appreciate the security research community's efforts in helping us keep PropFlow secure. If you discover a security vulnerability, please report it responsibly.

security@propflow.ke

Please include a detailed description of the vulnerability, steps to reproduce, and any supporting materials. We will acknowledge your report within 48 hours.

Contact Security Team