Security & trust

What's actually true today, not a certification we don't have.

Argon2 password hashing

Authentication uses Argon2, an industry-standard, memory-hard hashing algorithm designed to resist GPU-based cracking.

Role-based access control

Every user is scoped to their organization and their assigned role — access is explicit, not implicit.

Hardened public QR routes

The public QR-resolution endpoint carries strict security headers by design: no caching, no referrer leakage, and no search-engine indexing, because a token-bearing URL is treated as a secret.

Site-wide security headers

Content-Security-Policy, X-Frame-Options, and Permissions-Policy are enforced platform-wide, with an active CSP rollout in progress toward full enforcement.

PropertyLens does not yet hold SOC 2, ISO 27001, or similar third-party compliance certification. If certified compliance is a requirement for your organization, contact us — it's part of our roadmap, and we'll tell you honestly where we stand.

Found a security issue? Email security@propertylensapp.com.