Data Security
How CondoSteward protects your firm's records and your clients' data.
CondoSteward organizes records and workflow. It does not make legal, engineering, insurance, or compliance determinations. The answers below describe our technical and operational practices in plain language. We do not claim SOC 2 certification or HIPAA compliance, and we will not use language like “guaranteed secure” or “certified safe.” We are straightforward about what we do and do not provide.
Last reviewed: April 2026. If you have a security question not answered here, contact us at support@condosteward.com.
Data Storage and Access
All CondoSteward data — including documents, metadata, user records, and audit logs — is stored in managed cloud infrastructure hosted in the United States. We use industry-standard cloud providers that maintain physical security, environmental controls, and redundancy across their data centers. Your data does not leave U.S.-based infrastructure.
Yes. CondoSteward uses strict multi-tenant data isolation. Your firm’s associations, buildings, documents, and users are completely separated from all other firms in the system. A user at one firm cannot view, search, or access any data belonging to another firm. This separation is enforced at both the database and application level, not just through the interface.
CondoSteward’s internal team does not routinely access customer documents. System administrators may access data only for technical support, troubleshooting, or maintenance purposes — and only when necessary to resolve an issue you report or to maintain platform operations. We do not review, analyze, or share your documents for any purpose outside of providing the service.
Yes. All data is encrypted in two ways. In transit means data is encrypted using HTTPS/TLS whenever it travels between your browser and our servers, so it cannot be intercepted. At rest means data stored in our database and file storage is encrypted on disk using AES-256 or equivalent encryption provided by our cloud infrastructure. This applies to both your documents and all associated metadata and records.
Access Control and User Management
CondoSteward uses Clerk, a purpose-built authentication platform, to manage all user accounts and login security. Passwords are never stored directly in our database — Clerk handles secure credential storage, login session management, and email verification using industry-standard practices. All new user accounts go through an approval process before gaining access to your firm’s data.
Yes. CondoSteward uses a role-based access system with four defined roles: CAM Admin, CAM Staff, Board Read-Only, and Super Admin. Each role has specific permissions. CAM Admins can manage the team, export packets, and configure settings. CAM Staff can upload and tag documents and create tasks. Board members can view documents and the audit trail for their association only — they cannot upload, export, or edit anything. Role assignments are managed by your CAM Admin and can be changed at any time.
When a team member leaves, your CAM Admin can immediately deactivate their account. Deactivation removes all access to your firm’s data instantly. Everything that person uploaded, tagged, or organized remains in place and accessible to the remaining team. The audit trail preserves a record of all actions the departing user took while they had access, so nothing is lost and the history remains clear.
Board members can be given read-only access scoped to their specific association. They can view documents and the audit trail for their association only — they cannot see other associations, upload files, export packets, or change any settings. Attorney or outside reviewer access is not currently a built-in role, but documents can be shared through exported packets with a full audit trail of what was included and when it was exported.
Audit Trail and Continuity
Yes. CondoSteward maintains an immutable audit trail that records every significant action in the system: who uploaded a document, who tagged it, who changed its status, who exported a packet, and when each action occurred. This log cannot be edited or deleted by users. It is visible to CAM Admins and board members within their permitted scope, and it provides a clear chain of custody for every document in your vault.
Your data remains accessible through the end of your subscription period. CondoSteward is designed so you can export your documents and associated metadata in standard formats before your subscription ends. Your records belong to your firm and your associations — not to us. After the subscription period ends and any agreed data retention period expires, your data is securely deleted from our systems. Specific data export and retention terms are confirmed in your subscription agreement.
This is one of the core problems CondoSteward is designed to solve. Records are stored at the association level, not at the individual user level. When a manager or board member leaves, the association’s document history, audit trail, packet export history, and status tracking remain intact and accessible to the remaining team. New team members can be granted access immediately through an invitation, with a full record of what was on file and what was done before they arrived.
Hosting and Reliability
CondoSteward is hosted on Vercel (application layer) and uses managed cloud database and file storage services hosted in the United States. These providers maintain SOC 2-certified data centers with physical security, redundant power, network monitoring, and automated failover. We chose infrastructure providers with strong security track records so we can focus on building the best records workflow for your team.
CondoSteward is built on cloud infrastructure designed for high availability. Our hosting providers maintain uptime commitments in their service agreements, and we architect the platform to minimize single points of failure. While we do not currently publish a formal SLA with guaranteed uptime percentages, we monitor platform health continuously and address issues as they arise. If you experience a service disruption, contact support@condosteward.com.
Yes. CondoSteward’s cloud infrastructure scales automatically as your portfolio grows. Adding more associations, users, or documents does not require hardware changes or migration. The same platform that works for a firm managing 5 associations works for a firm managing 500 — with the same security controls, access management, and audit trail at every scale.
Compliance, Guardrails, and What We Do Not Claim
CondoSteward is designed with data privacy practices appropriate for the types of records CAM firms manage. We encrypt data in transit and at rest, enforce role-based access controls, maintain audit trails, and isolate each firm’s data from other firms. Florida does not currently have a comprehensive consumer data privacy statute equivalent to California’s CCPA, but we build to a standard that reflects current best practices for handling sensitive business records. If Florida enacts additional data privacy requirements, we will evaluate and adapt accordingly.
No. CondoSteward does not currently hold SOC 2 certification and is not HIPAA compliant. We are straightforward about this because we believe transparency matters more than overclaiming. Our infrastructure providers (cloud hosting, database, and authentication services) do hold SOC 2 certifications for their environments. As CondoSteward grows, we will evaluate pursuing our own SOC 2 certification when it is appropriate for the scale and needs of our customer base.
No software platform can guarantee absolute security, and we will not claim otherwise. CondoSteward implements industry-standard encryption, access controls, and audit logging — but we do not guarantee that our systems are immune to every possible attack, vulnerability, or data loss scenario. We do not make legal, engineering, insurance, or compliance determinations about your records. We do not certify that any document set is legally sufficient, complete, or compliant with any regulation. Professional review is always required for those determinations.
If you discover a potential security vulnerability, suspect unauthorized access to your account, or have any security-related concern, contact us immediately at support@condosteward.com with the subject line “Security Concern.” We take all reports seriously and will respond within one business day. If you believe your account has been compromised, also change your password immediately through the login page.
Ready to see how it works?
Schedule a 30-minute demo and see CondoSteward's security and access controls in action.
