Skip to content

Security

Community data belongs to the community

Nivaasos protects community data with invitation-only sign-in, role-based authorization enforced on the server for every request, strict per-community isolation, and an audit history of changes. The public website is completely separate from the authenticated application and never displays private records.

Invitation-only sign-in

There is no open registration. A community authorizes its members, and only those people can sign in — using Google sign-in, so Nivaasos never stores their passwords. Removing a member revokes access immediately.

Authorization on the server

Every request is checked against the member's community and role before any data is returned. Permissions are enforced in the application and data layer — not merely hidden in the interface — so changing a URL or API call cannot expose someone else's records.

Strict community isolation

Every record belongs to exactly one community, and all queries are scoped to it. Communities cannot see each other's data, and administrators reach only the communities they are authorized for.

Role-appropriate visibility

Administrators, managers, owners, residents, and auditors each see what their role allows. The auditor role is read-only by design, so independent review never requires write access.

Audit history

Creates, updates, and deletions are recorded in an audit trail — who did what and when — giving communities durable accountability across committee and manager changes.

Public and private, fully separated

This marketing website has no access to application data. All product illustrations here use fictional demonstration content, private application pages are excluded from search indexing, and privacy is enforced by authentication and authorization — never by obscurity.

Our commitments

What we promise — and what we don't claim

We commit to these principles: your community's data belongs to your community; access is controlled by role and authorization; financial information is visible only to authorized users; private community information is never displayed publicly; and actions maintain a clear history.

We deliberately avoid security buzzwords we haven't earned. You won't find claims of certifications or compliance standards on this site unless they are implemented and verified. If you have a security question — or believe you've found a vulnerability — write to rajmanda@gmail.com and we will respond.

For how we handle personal information on this website and in the product, see the Privacy Policy.

Give your community the clarity it deserves.

Bring payments, expenses, maintenance, documents, and communication into one transparent workspace your whole community can trust.