Trust Center
Security and privacy at HOA Desk.
HOA Desk stores governance, property, correspondence, financial, and utility records for its customers. This page describes our security controls, certifications, and service providers.
Last updated September 26, 2026
Compliance
Certifications and audits.
Current certifications are listed below. Reports and certificates are available under a non-disclosure agreement.
Report available
SOC 2 Type II
An independent auditor examines the design and operating effectiveness of a service organization’s controls across a defined review period.
Certified
ISO 27001
ISO 27001 specifies the requirements for establishing and maintaining an information security management system.
Report available
Penetration test
An authorized adversarial assessment of the application carried out by an independent security firm.
Documents
Reports, certificates, and policies.
Published documents open directly. Contact us to request any other document under a non-disclosure agreement. A member of our team will respond.
SOC 2 Type II report
The auditor’s report on the design and operating effectiveness of our controls.
On request
ISO 27001 certificate
The certificate issued for our information security management system.
On request
Penetration test report
The most recent independent adversarial assessment of the application.
On request
Security questionnaire
HOA Desk completes customer, counsel, and insurer questionnaires in the requesting party’s own format.
On request
Privacy policy
This policy sets out the categories of data HOA Desk processes, the purposes for processing, and the applicable retention.
Published
Subprocessor register
This register lists each third party engaged to process association data and the scope of data disclosed to it.
Published
Controls
Data security
Association records are segregated by tenant and retained for the life of the account.
Tenant isolation is enforced by the database
Every record is scoped to a single association by composite foreign key constraints that make a record belonging to two associations impossible to write.
Tenant scoping is verified by automated test
An inventory test scans the application’s SQL and requires every query against a tenant table either to name an association or to be registered as a documented exception.
Authorization is tested positively and negatively
The test suite traverses the navigation as each membership type and asserts both that permitted routes resolve and that withheld routes are refused when requested directly.
Write operations are recorded in an audit log
The application maintains a per-association audit log that attributes each change to a user and a time. The history remains available after a board change.
Records are retained for the life of the account
Association records remain available while the account is open and are deleted or returned on request when an association closes its account.
Subprocessors are disclosed before engagement
Any third party that will process association data is published on the subprocessor register before it begins receiving data.
Controls
Personnel access
HOA Desk staff cannot open the contents of any association’s records.
No administrative query returns customer content
The internal console reads account counts and configuration only, and no query exists anywhere in it that returns a project, message, answer, decision, or attachment.
Personnel hold no tenant membership
HOA Desk staff are recorded in a separate table, belong to no association, and a staff session resolves to no tenant context.
The administrative console is not discoverable
A request from anybody who is not staff receives the standard not-found response. Its status code and response length do not disclose the console.
Personnel actions are logged independently
Actions taken by HOA Desk staff are written to a separate operator log. They are not added to an association’s audit history.
Any expansion of this access will be disclosed first
We will update this page and notify affected associations before adding any way for staff to view association content. Use of that access would be logged.
Controls
Access control
Access is authenticated externally, scoped to a single association, and revoked on the next request.
Authentication is delegated to WorkOS
WorkOS AuthKit maintains user identity and any enrolled second factor. It has no access to association records.
Homeowner accounts are passwordless
Homeowners sign in through a single-use link delivered by email. These accounts have no reusable password.
Authorization is scoped per association
Role assignments are stored separately for each association. Access granted in one association grants no access to another.
Revocation takes effect on the next request
Every request reads current role assignments from the database. Removing a user therefore takes effect immediately.
Authorization checks are capability-based
Every route guard checks a specific capability. The functions that display a user’s status are separate from the functions that enforce access.
Committee seats require active membership
A committee seat grants no access after the user has been removed from the association, even if the seat record remains.
Controls
Product security
These controls address the application’s own attack surface.
Output is encoded by the rendering layer
The server-side renderer escapes interpolated values by default, and stored rich text is checked against a closed schema before it is rendered.
Project mail addresses are non-enumerable
Each project is issued an address containing 122 bits of entropy, and inbound mail is matched on that token. Sequential project numbers are not used for mail routing.
Unrecognized inbound mail is quarantined
A message from a sender who is not a participant on the project is held for review and must be accepted by a committee member before it enters the record.
Outbound mail is authenticated
Project correspondence is sent from a subdomain publishing a DMARC policy of reject. Mail that fails authentication for that origin is rejected.
No cardholder data reaches the platform
The payment provider collects card and bank details on its own pages. HOA Desk records design-review fees and deposits after receipt. Card numbers are not entered into or stored by HOA Desk.
AI output is identified and reviewed
Model-generated answers and draft minutes are identified where they are shown, and imported financial statements are checked against the source arithmetic and require a person to publish them.
Controls
Infrastructure
The platform runs on managed Cloudflare infrastructure with no self-managed servers.
Production runs on Cloudflare
The application runs as a Cloudflare Worker with records held in D1 and uploaded files in R2. HOA Desk does not operate a self-managed production server.
Data is encrypted in transit and at rest
All traffic is served over TLS, and Cloudflare encrypts both the records database and the object store at rest.
Correspondence is segregated to its own subdomain
Project mail uses a dedicated subdomain. Corporate email uses a different domain.
Integration credentials are isolated by association
Credentials for connected services are sealed in a separate store for each association. Google Workspace uses workload identity federation and does not require a stored service-account key.
Controls
Corporate security
Changes reach production only through a tested and version-controlled pipeline.
Automated testing gates every release
The automated test suite runs after every change. A failed test blocks deployment.
Schema changes are applied out of band
Deployment does not migrate the database. Changes to tables that hold association records require a separate action.
Deployment credentials are least-privilege
The release credential is scoped to the application alone and cannot modify the DNS or mail records for the domain.
Secrets are held outside the source tree
Application secrets are stored by the platform and are not committed to the repository. Repository access does not disclose those credentials.
The release pipeline is version-controlled
Release checks are configured in the repository. Changes to those checks are visible during review.
Legal
Third parties engaged to process association data.
Customers are notified before HOA Desk begins using a new subprocessor. The company is added to this register before it receives association data.
Cloudflare
Provides application hosting, record and object storage, and email routing for the application and this website.
Receives All application records and uploaded files, project correspondence, and request logs including IP addresses.
WorkOS
Provides authentication and second-factor enrollment for the application.
Receives Your name and email address, and a second authentication factor if you enroll one. No association records are disclosed to it.
Anthropic
Provides the language model used by the assistant, minutes drafting, and financial statement transcription.
Receives The material required to serve each request, such as the relevant portion of a governing document and the question asked, a meeting transcript, or the financial statement or board packet being transcribed.
Zego
Provides online dues payment for homeowners.
Receives The lot, the amount due, and the paying homeowner’s contact details. Card and bank details are entered on Zego’s own pages and are never received or stored by HOA Desk.
REPAY
Provides online dues payment for homeowners.
Receives The lot, the amount due, and the paying homeowner’s contact details. Card and bank details are entered on REPAY’s own pages and are never received or stored by HOA Desk.
Microsoft
Provides corporate email for HOA Desk.
Receives Messages you send to us, including contact form submissions from this website.
Application security
Report a security issue.
Email us about suspected vulnerabilities and include "Security" in the subject line. We will acknowledge the report and tell you the outcome. HOA Desk does not offer a paid bug bounty program.