Security & Compliance

How your data is protected.

How is my data protected?

All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Card and ACH data is never stored on HOAfy infrastructure — Stripe handles all payment data under PCI-DSS Level 1. Every API call is authorized server-side and association-scoped, so cross-community data access is impossible.

Is multi-factor authentication available?

Yes. TOTP-based MFA can be enabled for any account and is recommended for board and manager roles. Passwordless magic-link login is available for homeowners who want a lower-friction option.

Is there an audit log?

Yes. Every create, update, and delete is recorded with actor, IP, timestamp, and a before/after diff. Sensitive reads (financial reports, member exports, document downloads) are logged too. The audit log is retained for 7 years to satisfy state HOA record-retention statutes.

Where is HOAfy hosted?

HOAfy runs on AWS in US regions (us-east-1 primary). The platform uses managed services — Cognito for identity, DynamoDB for data, S3 for documents.

Can I export all my data?

Yes. Roster, financials, documents, and audit log can all be exported in standard formats (CSV, PDF, ZIP). Your data is yours — no lock-in, ever.

Still have questions?

Our team is happy to walk you through HOAfy and answer anything we missed.

Ready to simplify your HOA?

Start your free trial today. No credit card required.