Domi

Security

Domi is under active development and has not yet processed a live rent payment or handled real resident data. The commitments below describe how Domi is built, not a running system with a track record yet — see below for what is and isn't live.

Domi is built so that data in transit is always encrypted with TLS, and data at rest — resident records, leases, and maintenance tickets — is encrypted at rest by our database provider.

Every organization's data is isolated at the database level using Postgres row-level security. Every table that holds organization data is scoped to that organization by policy, not just by application code — so a bug in the app layer can't leak one landlord's or property manager's data into another's.

Domi is designed so that it never sees or stores payment card numbers or bank account details. Rent payments are handled by Stripe, and rent funds are built to settle directly into each landlord's or property manager's own Stripe account — Domi records that a payment happened, but is never in a position to hold resident funds.

Automated, recurring backups are part of the infrastructure plan before any real data is stored.

Domi does not currently hold SOC 2 or any other third-party security certification. If that changes, it will be reflected here.

To report a security issue or ask a question, contact us at team@aruon.ai or see the contact page.