Security
Devv PropOS is being built with tenant boundaries, role-aware access, server-side workflows, and auditability as core product requirements.
PropOS records are scoped to organizations. Access rules are designed so authenticated users only work inside the agency context they belong to.
Business writes are handled through server-side workflows that validate input and scope organization, branch, ownership, and audit fields before data changes are made.
The product supports principal, administrator, branch manager, and agent operating roles. These roles are used to shape visibility and management actions.
Important operational and security-sensitive actions are intended to leave an audit trail so agencies can understand what changed and who was accountable.
Uploaded record documents are intended to be stored in private storage and accessed through authenticated, role-aware application flows. Agencies should still avoid uploading unnecessary sensitive files and should apply their own retention rules.
Devv PropOS uses reasonable safeguards for a pilot-stage product, but no online platform can guarantee absolute security. Agencies should report suspected unauthorized access or document exposure promptly.