Records and access

What we hold, and who can reach it.

Sign in from a phone at an annual meeting and your session reaches the records of the communities you hold a seat on — nothing beyond them. The database checks that on every single request, so a page you were never meant to see cannot be talked into loading.

01

You

Board · Community manager · Vendor

02

TLS 1.3

Encrypted in transit

03

Scoped access

Per community, per role

04

AES-256

Encrypted at rest

05

Verified actions

Server-validated payouts

Defense in depth

How your data is protected

Every request runs the same checks, from the browser to the payout.

The controls

6 controls behind every screen

Encryption

Everything travels to us over TLS 1.3 and is stored encrypted with AES-256 by our hosting and database providers.

Who sees what

A community manager reaches their own communities and nobody else’s, and a vendor reaches the work orders its own company was awarded. The limit travels with the account, so it holds on every screen and every export.

Approvals and payouts

Approving a work order and releasing a payout both happen on our servers, where the rules live — nothing a browser sends can approve its own payment. Every payment leaves a record your board can open. Roles, verification decisions and insurance status are written to an audit log the database itself refuses to edit or delete.

Where it runs

The site runs on Vercel. Your records sit in a Supabase database on AWS, managed by them rather than on a server we keep ourselves.

Signing in

Sign in with a password, or with a one-time link emailed to you. Either way the session belongs to your account and expires on its own, and signing out ends it there and then.

Certificates

The insurance certificate for a vendor working at your community opens from your dashboard, with the date it runs out on it. When one lapses and its renewal window closes, that company cannot propose on new work until a current certificate is verified.

Verification

What does verification prove?

That the document exists, that a person here read it, and that the date on it has not passed. How well a company mows a lawn is your board’s judgement, made from the proposals and the visit records.

What closes a proposal

  • General liabilityRequired in every trade before a company can propose. A policy that lapses has 30 days to be renewed. After that, proposals close.
  • Workers’ compensationRequired in every trade before a company can propose. A policy that lapses has 30 days to be renewed. After that, proposals close.
  • The trade credentialA CPO card for pool, auto liability for landscaping and a background check for porter and amenity staffing. Auto liability carries the same 30-day window as the other insurance lines. A trade certification gets none, because an expired one is not a certificate.

A staffing company that puts lifeguards on a pool deck files a fourth document as well: a current lifeguard certification.

On file, and closing nothing

  • Business registrationBusiness registration is collected and verified as well. A proposal turns on the insurance and the trade credential; the registration says which company a community would be signing with.
  • W-9A W-9 is collected and verified in the same review.

A person at HOAcrew opens the certificate and takes the limits and the expiration date straight off the document. Where that disagrees with what the vendor typed, the certificate wins. From there the vendors propose, and your management team picks the one it wants.

Read a certificate yourself

Responsible disclosure

Found something? Tell us.

If you discover a security vulnerability, please report it responsibly to admin@hoacrew.com. Every report is read by a person and acknowledged.

    Security | HOAcrew