Security

Your data security is our top priority

Last Updated: January 2026

Encryption

  • 256-bit SSL/TLS encryption for all data in transit
  • AES-256 encryption for data at rest
  • Secure key management and rotation
  • End-to-end encryption for sensitive financial data

Infrastructure Security

  • Enterprise-grade cloud infrastructure
  • Geographic redundancy and failover systems
  • Regular security audits and penetration testing
  • 24/7 infrastructure monitoring and alerting
  • DDoS protection and mitigation

Authentication & Access

  • Secure password hashing with bcrypt
  • JWT token-based authentication
  • Role-based access control (Owner, Manager, Vendor)
  • Session management and automatic timeout
  • Brute force protection and rate limiting

Privacy Controls

  • Minimal data collection principle
  • User consent management
  • Data retention policies
  • Right to data portability
  • Right to erasure (GDPR compliant)

Payment Security

  • PCI-DSS compliant payment processing
  • All payments handled by Stripe
  • No credit card data stored on our servers
  • Secure tokenization of payment methods
  • Fraud detection and prevention

User Responsibility

Users are responsible for: • Maintaining account security and strong passwords • Managing access permissions (owners, managers, vendors) • Verifying all data entered into the platform • Reporting any suspicious activity immediately • Keeping login credentials confidential VillaPilot.ai is not responsible for misuse of the platform by authorized users.

Report Security Issues

If you discover a security vulnerability, please report it to us immediately at:

support@villapilot.ai