Security
This page is maintained by Property Legals Ltd to answer common security questions about the portal.
Last updated: July 2026. This is a plain-English summary of our current controls, not an independent certification.
Access and authentication
- Email + password with password strength checks and support for optional Google sign-in.
- Passwords are hashed by our authentication provider — we never store plaintext passwords.
- Session tokens are short-lived and rotated. You can sign out from any device at any time.
Data protection
- All traffic to and from the portal uses TLS 1.2+.
- Databases are encrypted at rest.
- Row-level access controls scope every user (client, agent, partner, admin) to only their own data.
Payments
We do not process card payments on-site. Bank details captured for referral payouts are stored under access-controlled records and never exposed to other users.
Monitoring
We log authentication events, admin actions and API errors. Unusual patterns are alerted to the on-call team.
Responsible disclosure
If you believe you have found a security vulnerability, please email security@property-legals.com. We ask that you give us a reasonable time to fix issues before public disclosure and that you do not test against real user data.
Data-protection contact
Data-protection queries: privacy@property-legals.com. See also our Privacy notice.
