Security & Compliance
How your data is protected.
How is my data protected?
All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Card and ACH data is never stored on HOAfy infrastructure — Stripe handles all payment data under PCI-DSS Level 1. Every API call is authorized server-side and association-scoped, so cross-community data access is impossible.
Is multi-factor authentication available?
Yes. TOTP-based MFA can be enabled for any account and is recommended for board and manager roles. Passwordless magic-link login is available for homeowners who want a lower-friction option.
Is there an audit log?
Yes. Every create, update, and delete is recorded with actor, IP, timestamp, and a before/after diff. Sensitive reads (financial reports, member exports, document downloads) are logged too. The audit log is retained for 7 years to satisfy state HOA record-retention statutes.
Where is HOAfy hosted?
HOAfy runs on AWS in US regions (us-east-1 primary). The platform uses managed services — Cognito for identity, DynamoDB for data, S3 for documents.
Can I export all my data?
Yes. Roster, financials, documents, and audit log can all be exported in standard formats (CSV, PDF, ZIP). Your data is yours — no lock-in, ever.
Still have questions?
Our team is happy to walk you through HOAfy and answer anything we missed.