Безпека в Landager
Останнє оновлення: October 3, 2026
1. Overview
Landager stores property, tenant and financial records for landlords. This page describes, plainly, how we protect that data today and what we are still improving. It describes the system as it runs now; it is not a certification.
2. Infrastructure
- Our application servers and PostgreSQL database run on servers rented from Hetzner Online GmbH in Germany.
- Traffic reaches us through Cloudflare, which provides DNS, TLS termination and network-level protection.
- Uploaded files (lease documents, photos, receipts, ID documents from applications) are stored in a private Cloudflare R2 bucket that has no public access.
3. Encryption
- In transit: every connection to the website, the dashboard and the tenant portal uses HTTPS (TLS).
- Passwords: stored only as bcrypt hashes; we cannot read them.
- Sensitive applicant data: ID numbers, dates of birth, income, employer, address and phone from tenant applications are encrypted in the database (AES-256-GCM), with keys kept outside the database.
- Backups: encrypted (GPG, AES-256) before they leave our servers.
4. Accounts & Access
- Signing in with a password also requires a second step: a one-time code sent to your email, or, if you turn it on, a code from an authenticator app (with one-time recovery codes). You can also sign in with Google.
- Repeated failed sign-in attempts lock the account temporarily.
- Sessions expire after 3 days without use and 14 days at most. Changing or resetting your password signs you out everywhere, and you can sign out of every device from Settings.
- If our support team needs to look at your account, the session is read-only by default, ends after 30 minutes, shows a banner, and is recorded in your account's activity log. Support can never change billing, passwords or two-step settings, export or delete your account.
- Tenants use a separate portal with their own sessions; they can see only their own lease and payments.
- Our internal admin tools use separate credentials from customer accounts, require two-factor authentication, and sit behind an access gate (Cloudflare Access).
5. Data Isolation
- Every request that reads or changes a record checks that the record belongs to the signed-in account.
- Files open only through short-lived signed links issued after that ownership check.
- Public forms (tenant applications, maintenance requests) are protected by single-use links, email verification codes, rate limits or bot protection.
- Uploaded files are checked by their content (not just their name), scanned for malware, and counted against a storage limit per account.
6. Backups
The database is backed up every day. Each backup is encrypted and copied off-site, and restoring from an off-site backup has been tested.
7. Payments & AI
- Subscriptions are processed by Lemon Squeezy, our merchant of record. Card details go to Lemon Squeezy, never to our servers.
- The AI assistant sends your question and the portfolio details needed to answer it to Google's Gemini API. See the Privacy Policy for what is sent and stored.
8. What We Are Improving
We would rather tell you than overstate. Work currently planned includes:
- A tamper-evident audit log covering every change, with an account activity page for you.
- A stricter content security policy for the dashboard (no inline scripts).
9. Reporting a Vulnerability
If you believe you have found a security problem, please email [email protected] with the subject "Security". Please give us a reasonable time to fix it before disclosing it publicly. We do not take legal action against good-faith research.
