Security
Your data, protected like it's ours.
Rent records, tenant details, and payment history are sensitive. Here's exactly how we protect them — no vague promises, just what's actually in place.
Encryption in transit and at rest
Every connection to VilliQ runs over TLS 1.3. Data at rest is encrypted with AES-256, the same standard used by banks.
Every organization is isolated
No landlord, agency, or manager can see another organization's properties, tenants, or financial data — enforced on every single request, not just in the interface.
Payments never touch our servers
Card and bank transfer details are handled entirely by Paystack and Flutterwave, both PCI-DSS compliant. We only ever see a payment reference, never a card number.
Role-based access control
Property managers, agents, maintenance staff, and tenants each get exactly the access their role needs — nothing more.
Independent authentication
Sign-in is handled by Supabase Auth with hashed, salted credentials. We never store your password in plain text, and we can't see it either.
Responsible disclosure
Found a vulnerability? Email security@villiq.com and we'll respond within one business day.
Reporting a vulnerability
If you believe you've found a security issue in VilliQ, please email security@villiq.com with details and steps to reproduce. We ask that you give us a reasonable window to investigate and fix the issue before disclosing it publicly. We don't currently run a paid bug bounty program, but we credit every genuine report.