PGManage

Security

You are storing residents’ ID. Here is how we hold it.

A PG keeps Aadhaar-linked KYC, photographs of ID documents, and the phone number of everyone in the building. That is sensitive, and treating it carelessly would be the fastest way to lose your trust. This page is what we actually do — and where something is not done yet, it says so.

Your data stays in India

PGManage runs in Amazon Web Services’ Mumbai region (ap-south-1). Resident records, KYC and payment data are stored and processed in India — they do not leave the country in normal operation.

Encrypted in transit and at rest

Every connection is HTTPS with HSTS enforced — there is no unencrypted way in. The database volume is encrypted at rest, and application secrets (payment keys, the WhatsApp token) live in AWS Secrets Manager, write-only over the API, never shown back after they are set.

One property’s data cannot touch another’s

Each organisation’s data lives in its own isolated database schema. A request is pinned to one organisation for its entire life, so there is no query path from your account into anyone else’s — the separation is structural, not a filter someone could forget to apply.

Role-based access, scoped to the property

Owners, managers and collection staff each see only what their role allows. A staff member is limited to the properties you assign them; financial screens are gated to the roles that should see money. Access is a login per person, not a shared password.

Every action is logged, before and after

The audit log records who did what, with the value before and after, and flags sensitive actions. A recorded payment cannot be silently edited, and a deleted record can be restored. If something looks wrong, there is a trail to check it against.

Your data is yours to take

You can export residents, ledgers, payments and expenses as spreadsheets at any time — including the day you decide to leave. After cancellation we retain your data for a short grace period in case you return, then delete it.

What we will not pretend

We are an operator who built a tool, not a security vendor with a wall of badges. We do not claim certifications we do not hold. If you need something specific — a signed data processing agreement, a penetration-test summary, a defined backup schedule in writing — ask us directly and we will tell you plainly where we are, including where we are not there yet.

Security questions go to pgmanage36@gmail.com.