Security
Last Updated: September 30, 2026
A board trusting us with its association’s money and records should be able to see how that’s handled. Here is what we do, and what we don’t have yet.
Do you have a SOC 2 report?
Not yet. The HOA Wiz has not been through a SOC 2 audit and has no SOC report of its own. The companies that process payments and host our database do publish their own reports, and we name them below as theirs, not ours.
Your association’s money
- Each association connects its own Stripe account. When a resident pays dues, a fine or an assessment, the charge is made on the association’s account, and Stripe pays it out to the association’s bank. The HOA Wiz does not hold association money.
- Our fee is split off by Stripe at the moment of payment.
- Autopay charges run on the association’s account the same way.
Card and bank details
- Card and bank details are typed into Stripe’s own payment form. They go straight to Stripe. We never see or store a full card number or CVC.
- Saved payment methods are kept by Stripe, on the association’s Stripe account.
- We only act on payment updates that Stripe has signed, and we check that signature before recording anything.
Who can see what
- Every table in our database has row-level security turned on. There are 597 access rules at the database itself that decide which rows each signed-in person may read or change. The app screen is not what keeps records private.
- New database functions are closed to the app by default. Each one is opened to signed-in users on purpose, one at a time.
- Two accounts have platform admin access: mine, and one system account.
What we log
- Changes to a payment’s status, and the steps of a board vote: created, opened, cast, changed, closed and deleted.
- Personal data exports, when someone downloads their own data.
- Emails the app sends, and the payment events Stripe sends us.
- App errors, through Sentry. Error reports are filtered for passwords, tokens and similar fields before they’re sent. Session recording is off.
How changes are checked
- Every change to the app’s code runs automated checks on GitHub, including a scan of the code libraries we use for known security problems.
- Every night, an automated check compares the live database’s structure against our test copy and flags any difference.
- Every week, another compares the server code that’s actually running against the code we wrote, and flags any difference.
The companies we build on
- Stripe processes every card and bank payment made in the app. Stripe states it is certified as a PCI Service Provider Level 1, encrypts card numbers at rest with AES-256, and produces SOC 1 and SOC 2 Type II reports each year, with a public SOC 3. See Stripe’s security page.
- Supabase hosts our database, sign-in and file storage, on Amazon Web Services in Northern California (us-west-1). Supabase states that customer data is encrypted at rest with AES-256 and in transit with TLS, and that it holds a SOC 2 Type 2 report. See Supabase’s security page.
Those reports and certifications belong to Stripe and Supabase. They describe their systems, not The HOA Wiz.
Reporting a problem
If you think you’ve found a security problem, or you’d like more detail for a board meeting, please write to me.
Privacy Policy
Terms of Service
Support
The HOA Wiz