Security measures include encryption in transit and at rest,
strict per-account access controls so each landlord only accesses their own records (every request is scoped to the signed-in account), short-lived signed links for media, rotating tenant portal tokens, and no storage of card details. The account a landlord nominates to receive rent (BSB, account number, PayID) is
additionally encrypted by the application before it is stored, with the key held outside the database. Two things are kept off our systems by design:
identity documents are never stored by us — landlords and applicants alike verify directly with an accredited provider, who keeps the document — and
we never hold or control rent money, which moves bank-to-bank between the tenant's and landlord's accounts. See our
Security page for detail.
Retention: tenancy records — ledgers, messages, notices, condition reports, and inspection records including photos and videos — are kept for the life of the account plus
seven years after a tenancy ends. That reflects the limitation periods for bond and tribunal/court claims (up to six years in most states), so the dated condition evidence is available if a dispute arises long after the tenancy. When an account closes, we delete or de-identify personal information within a reasonable period, except records we (or the landlord) must keep by law. A data breach likely to cause serious harm is notified to affected people and the OAIC under the Notifiable Data Breaches scheme.