Back to Home

Security

Last updated 4 August 2026

Victor Markus holds information that matters: leases, rent payments, bank transaction feeds and the personal details of tenants who never chose us as a vendor. This page describes how we protect it. We have written it to be accurate rather than reassuring, so anything we have not finished yet is listed plainly at the bottom.

What we never hold

  • Card numbers. Card details go directly to Stripe, our payment processor. They never touch our servers.
  • Bank login credentials. When you connect a bank account, you sign in with your bank through Plaid. Your banking username and password are never transmitted to or stored by us.

How your data is separated

Access is enforced in the database itself, through row-level security, rather than by hiding things in the interface. Every request is evaluated against who you are and what you hold a record on. A tenant sees only their own tenancy. A contractor sees only the projects they have been invited to. Removing someone from a property takes effect on their very next request.

Technical controls

  • All traffic is encrypted in transit over TLS.
  • Third-party credentials are held as encrypted secrets, never in source code.
  • Bank access tokens are stored encrypted and are never exposed to the browser.
  • Incoming messages from our payment and banking providers are cryptographically verified before we act on them.
  • The database is backed up automatically with point-in-time recovery.
  • Features that move money are gated behind explicit switches that default to off.

Who we share data with

We use a small number of processors, each for a specific purpose:

  • Supabase, database, sign-in, file storage
  • Vercel, application hosting
  • Stripe, card and bank payments
  • Plaid, bank account connections and transaction feeds
  • Resend, transactional email
  • Anthropic, the Markus assistant, scoped to your own records

We do not sell personal data, and we never have.

Our policies

We maintain a written Information Security Policy and Access Control Policy. They are internal documents, because they describe our controls in detail, but we provide them to customers, partners and prospective partners on request. Email security@victormarkus.com.

What we are working on

Victor Markus is an early-stage company in beta. These are real gaps, and we would rather name them than let you assume otherwise:

  • Multi-factor authentication is not yet available on accounts. It is our next security priority.
  • Formal access reviews begin on a quarterly cadence from September 2026.
  • A documented backup restoration drill. We have backups; we have not yet rehearsed a full restore and timed it.

Reporting a vulnerability

If you believe you have found a security issue, email security@victormarkus.com. Please give us a way to reproduce it. We will acknowledge within two business days. We will not pursue action against anyone who reports a genuine issue in good faith and does not access or alter other people's data while doing so.

See also our Privacy Policy and Terms of Service.