Security

Your data, protected like it's ours.

Rent records, tenant details, and payment history are sensitive. Here's exactly how we protect them — no vague promises, just what's actually in place.

Encryption in transit and at rest

Every connection to VilliQ runs over TLS 1.3. Data at rest is encrypted with AES-256, the same standard used by banks.

Every organization is isolated

No landlord, agency, or manager can see another organization's properties, tenants, or financial data — enforced on every single request, not just in the interface.

Payments never touch our servers

Card and bank transfer details are handled entirely by Paystack and Flutterwave, both PCI-DSS compliant. We only ever see a payment reference, never a card number.

Role-based access control

Property managers, agents, maintenance staff, and tenants each get exactly the access their role needs — nothing more.

Independent authentication

Sign-in is handled by Supabase Auth with hashed, salted credentials. We never store your password in plain text, and we can't see it either.

Responsible disclosure

Found a vulnerability? Email security@villiq.com and we'll respond within one business day.

Reporting a vulnerability

If you believe you've found a security issue in VilliQ, please email security@villiq.com with details and steps to reproduce. We ask that you give us a reasonable window to investigate and fix the issue before disclosing it publicly. We don't currently run a paid bug bounty program, but we credit every genuine report.

Have a security question before you sign up?