Current safeguards
- Protected workspace routes require a signed-in account and active buyer access.
- Every record and file request is checked against the signed-in owner on the server.
- Uploaded file bytes are kept separately from searchable listing data.
- Purchase keys and optional provider API credentials are encrypted before storage with separate encryption keys.
- Provider credentials are never returned to the browser after saving; only the final four characters are shown.
- Temporary PropCon pages use long random links, exclude private documents and expire after 24 hours.
- Public marketing exports require factual, media and marketing confirmations.
- Users can permanently delete individual listings or all app data.
Safe use by agents
Use an agency-approved device and account, lock unattended devices, upload only information required for the opportunity or listing, keep PropCon contact and POPIA outcomes accurate, check every recipient and destination, and remove sensitive records when the approved handoff is complete.
What the app does not do
It does not change PropCon on its own. The separately installed connected Call Desk acts only after the agent selects a PropCon outcome and confirms Save; it then sends only a booked CMA meeting or callback into the signed-in Agent Center. The app does not publish a listing, syndicate to portals, verify a seller or buyer’s identity, replace a mandate, create or legally validate an Offer to Purchase, provide legal compliance or guarantee that a third-party destination is secure.
Reporting a concern
Use the support form with the category “Problem”. Describe the affected listing without pasting passwords, identity numbers or private documents. Access can be revoked and app data deleted from the listings library.
Security programme
Security controls will continue to mature with independent review, documented incident response, access logging and brokerage administration as the service grows.
Last updated: 21 August 2026