Skip to content

Trust Center

Security and privacy at HOA Desk.

HOA Desk stores governance, property, correspondence, financial, and utility records for its customers. This page describes our security controls, certifications, and service providers.

Last updated September 26, 2026

Compliance

Certifications and audits.

Current certifications are listed below. Reports and certificates are available under a non-disclosure agreement.

  • Report available

    SOC 2 Type II

    An independent auditor examines the design and operating effectiveness of a service organization’s controls across a defined review period.

  • Certified

    ISO 27001

    ISO 27001 specifies the requirements for establishing and maintaining an information security management system.

  • Report available

    Penetration test

    An authorized adversarial assessment of the application carried out by an independent security firm.

Documents

Reports, certificates, and policies.

Published documents open directly. Contact us to request any other document under a non-disclosure agreement. A member of our team will respond.

Controls

Data security

Association records are segregated by tenant and retained for the life of the account.

  • Tenant isolation is enforced by the database

    Every record is scoped to a single association by composite foreign key constraints that make a record belonging to two associations impossible to write.

  • Tenant scoping is verified by automated test

    An inventory test scans the application’s SQL and requires every query against a tenant table either to name an association or to be registered as a documented exception.

  • Authorization is tested positively and negatively

    The test suite traverses the navigation as each membership type and asserts both that permitted routes resolve and that withheld routes are refused when requested directly.

  • Write operations are recorded in an audit log

    The application maintains a per-association audit log that attributes each change to a user and a time. The history remains available after a board change.

  • Records are retained for the life of the account

    Association records remain available while the account is open and are deleted or returned on request when an association closes its account.

  • Subprocessors are disclosed before engagement

    Any third party that will process association data is published on the subprocessor register before it begins receiving data.

Controls

Personnel access

HOA Desk staff cannot open the contents of any association’s records.

  • No administrative query returns customer content

    The internal console reads account counts and configuration only, and no query exists anywhere in it that returns a project, message, answer, decision, or attachment.

  • Personnel hold no tenant membership

    HOA Desk staff are recorded in a separate table, belong to no association, and a staff session resolves to no tenant context.

  • The administrative console is not discoverable

    A request from anybody who is not staff receives the standard not-found response. Its status code and response length do not disclose the console.

  • Personnel actions are logged independently

    Actions taken by HOA Desk staff are written to a separate operator log. They are not added to an association’s audit history.

  • Any expansion of this access will be disclosed first

    We will update this page and notify affected associations before adding any way for staff to view association content. Use of that access would be logged.

Controls

Access control

Access is authenticated externally, scoped to a single association, and revoked on the next request.

  • Authentication is delegated to WorkOS

    WorkOS AuthKit maintains user identity and any enrolled second factor. It has no access to association records.

  • Homeowner accounts are passwordless

    Homeowners sign in through a single-use link delivered by email. These accounts have no reusable password.

  • Authorization is scoped per association

    Role assignments are stored separately for each association. Access granted in one association grants no access to another.

  • Revocation takes effect on the next request

    Every request reads current role assignments from the database. Removing a user therefore takes effect immediately.

  • Authorization checks are capability-based

    Every route guard checks a specific capability. The functions that display a user’s status are separate from the functions that enforce access.

  • Committee seats require active membership

    A committee seat grants no access after the user has been removed from the association, even if the seat record remains.

Controls

Product security

These controls address the application’s own attack surface.

  • Output is encoded by the rendering layer

    The server-side renderer escapes interpolated values by default, and stored rich text is checked against a closed schema before it is rendered.

  • Project mail addresses are non-enumerable

    Each project is issued an address containing 122 bits of entropy, and inbound mail is matched on that token. Sequential project numbers are not used for mail routing.

  • Unrecognized inbound mail is quarantined

    A message from a sender who is not a participant on the project is held for review and must be accepted by a committee member before it enters the record.

  • Outbound mail is authenticated

    Project correspondence is sent from a subdomain publishing a DMARC policy of reject. Mail that fails authentication for that origin is rejected.

  • No cardholder data reaches the platform

    The payment provider collects card and bank details on its own pages. HOA Desk records design-review fees and deposits after receipt. Card numbers are not entered into or stored by HOA Desk.

  • AI output is identified and reviewed

    Model-generated answers and draft minutes are identified where they are shown, and imported financial statements are checked against the source arithmetic and require a person to publish them.

Controls

Infrastructure

The platform runs on managed Cloudflare infrastructure with no self-managed servers.

  • Production runs on Cloudflare

    The application runs as a Cloudflare Worker with records held in D1 and uploaded files in R2. HOA Desk does not operate a self-managed production server.

  • Data is encrypted in transit and at rest

    All traffic is served over TLS, and Cloudflare encrypts both the records database and the object store at rest.

  • Correspondence is segregated to its own subdomain

    Project mail uses a dedicated subdomain. Corporate email uses a different domain.

  • Integration credentials are isolated by association

    Credentials for connected services are sealed in a separate store for each association. Google Workspace uses workload identity federation and does not require a stored service-account key.

Controls

Corporate security

Changes reach production only through a tested and version-controlled pipeline.

  • Automated testing gates every release

    The automated test suite runs after every change. A failed test blocks deployment.

  • Schema changes are applied out of band

    Deployment does not migrate the database. Changes to tables that hold association records require a separate action.

  • Deployment credentials are least-privilege

    The release credential is scoped to the application alone and cannot modify the DNS or mail records for the domain.

  • Secrets are held outside the source tree

    Application secrets are stored by the platform and are not committed to the repository. Repository access does not disclose those credentials.

  • The release pipeline is version-controlled

    Release checks are configured in the repository. Changes to those checks are visible during review.

Legal

Third parties engaged to process association data.

Customers are notified before HOA Desk begins using a new subprocessor. The company is added to this register before it receives association data.

  • Cloudflare

    Provides application hosting, record and object storage, and email routing for the application and this website.

    Receives All application records and uploaded files, project correspondence, and request logs including IP addresses.

  • WorkOS

    Provides authentication and second-factor enrollment for the application.

    Receives Your name and email address, and a second authentication factor if you enroll one. No association records are disclosed to it.

  • Anthropic

    Provides the language model used by the assistant, minutes drafting, and financial statement transcription.

    Receives The material required to serve each request, such as the relevant portion of a governing document and the question asked, a meeting transcript, or the financial statement or board packet being transcribed.

  • Zego

    Provides online dues payment for homeowners.

    Receives The lot, the amount due, and the paying homeowner’s contact details. Card and bank details are entered on Zego’s own pages and are never received or stored by HOA Desk.

  • REPAY

    Provides online dues payment for homeowners.

    Receives The lot, the amount due, and the paying homeowner’s contact details. Card and bank details are entered on REPAY’s own pages and are never received or stored by HOA Desk.

  • Microsoft

    Provides corporate email for HOA Desk.

    Receives Messages you send to us, including contact form submissions from this website.

Application security

Report a security issue.

Email us about suspected vulnerabilities and include "Security" in the subject line. We will acknowledge the report and tell you the outcome. HOA Desk does not offer a paid bug bounty program.