What follows is architecture, and it is checkable. It is not a list of certifications, and we have not dressed it up as one.
How it is built
Separation between landlords is PostgreSQL row-level security, tied to the session, rather than a filter the application has to remember to apply. An application bug cannot read past it, because the enforcement is not in the application.
The equality impact assessment and the reasonable-adjustment records carry no DELETE grant. Not hidden in the interface — not granted in the database. A record that later becomes inconvenient cannot be quietly removed, by anybody.
Actions, statutory holds, acknowledgements and automatic closures are recorded as dated events rather than as state that changes silently. Every one of them is something a person can be asked about.
Residents do not have accounts and do not see this product. That reduces the exposed surface considerably — and it is also a real limitation, which we say on the legal spine page: a product tenants cannot see cannot offer them a right to contest a decision.
What we are not claiming
We are not listing standards, badges or accreditations here. If your review needs a specific one, ask us directly and you will get a straight answer about what does and does not exist rather than a logo.
Everything above is demonstrable in the product. It is not a substitute for your own security review, penetration testing evidence or data protection impact assessment.
Keeping a human in every decision is a genuine safeguard. It is not the same as the specific automated decision-making obligations that sit with you as controller, and we do not present it as such.
We would rather answer it early than at contract stage.
Tell us about your organisation and what you are trying to fix. It goes straight to the team, and a person replies.