Your data, your residents' privacy, treated like it matters.
Bank-grade encryption, every admin action audit-logged, PCI handled by Stripe, GDPR + CCPA data portability shipped on day one.
Encryption at rest + in transit
Postgres encrypted at rest (AES-256). All API + browser traffic over TLS 1.2+. Secrets stored only in our cloud KMS — never in code.
PCI scope reduction via Stripe
We never see or store card numbers. Stripe handles all PCI scope (SAQ-A). Resident payment data is tokenized end-to-end.
GDPR + CCPA portability
Any resident can export their full data or request deletion from /me/profile. Operators can do the same for the entire org.
Audit log on every admin action
Who did what, when, from which IP. Permit revokes, enforcement actions, payouts, and config changes are all immutably logged.
Incident response
24-hour status page updates on any incident. 72-hour post-mortem on every Sev-1. Direct contact at security@parkdwell.com.
SOC 2 Type II — in progress
We're going through our SOC 2 Type II audit now (target: end of Q3). Until then, our trust center has our control narrative.
Questions, answered
Frequently asked
Where is my data hosted?
Do you have penetration testing?
Can I get a DPA?
What happens if I cancel?
Are you HIPAA / FERPA / etc. compliant?
The fine print
Legal documents
Have a procurement question?
Send us your security questionnaire — we typically return them within 3 business days.