Last updated:
Dasibell takes the security of your lease operations data seriously. This page describes the technical and organisational measures currently in place to protect information stored in LeaseFlow OS. Security improvements are ongoing and this page will be updated as our controls mature.
Scope: LeaseFlow OS is a commercial lease operations platform. It does not process payments, hold financial funds, or expose a public marketplace. All payment-related data in the platform consists of references and records entered by users for internal tracking purposes only.
TLS Connections
Hashed Passwords
Session Authentication
Audit Logging
Role-Based Access
Per-Org Data Separation
Connections and Transport
- In transit: All communication between your browser and LeaseFlow OS is encrypted using TLS. Plain HTTP connections are not accepted.
- Storage: The platform is deployed on a managed cloud infrastructure. Infrastructure-level storage controls are applied by the hosting provider. We do not make claims about specific encryption standards beyond what the hosting provider verifiably provides.
- Passwords: User passwords are hashed using bcrypt. Plaintext passwords are never stored or logged.
Authentication and Access Control
- Workspace Isolation: Each organisation is a separate, isolated workspace tied to an internal ID. Data from one organisation cannot be accessed by users of another organisation.
- Role-Based Access: LeaseFlow OS enforces strict role-based access control. Finance can approve payments and upload references, while Property Managers cannot alter invoices once issued. Administrators retain full audit oversight.
- Session Control: Sessions are managed securely. All sensitive administrative actions trigger specific audit logs.
Evidence & Operations
- Immutable Records: Generated contract versions and invoices are securely retained. Payment references cannot be silently altered without leaving an audit trace.
- No Financial Execution: LeaseFlow OS records operational and external payment-reference data. It does not initiate transfers, collect cash, hold funds, or automatically confirm settlement.
Procurement & Compliance
Portfolio and Enterprise buyers can request a review of currently implemented controls and submit reasonable security or data-processing questionnaires. Responses reflect the platform’s current implementation and available evidence.
For security-related inquiries, contact support@dasibell.com.
- Invitation-only registration: new users can only join an organisation via a time-limited, single-use invite link sent to their email address.
- All administrative actions — user changes, contract edits, financial entries — are recorded in an audit log with timestamps and user attribution.
Infrastructure Security
- LeaseFlow OS is deployed on a managed cloud platform with automatic security patching.
- Database access is restricted to application-layer connections only. No direct public database access is permitted.
- Environment secrets (SMTP credentials, API keys, session secrets) are managed securely and are never committed to source code.
What We Don't Claim
We do not currently hold SOC 2, ISO 27001, or other formal security certifications. We do not claim bank-grade or regulated financial-grade security controls. We do not guarantee specific uptime or recovery time objectives. Security improvements are ongoing.
Responsible Disclosure
If you discover a security vulnerability in LeaseFlow OS, please report it responsibly to support@dasibell.com. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it.