Security posture
DuePact uses security practices appropriate for sensitive resident ledger workflows: encryption in transit, role-based access, MFA-ready account controls, approval and override logs, and human-reviewed packet actions. Formal certification claims should only appear after the current report type, date, scope, and public badge permissions are supplied.
Infrastructure
DuePact is hosted on AWS. Application traffic is encrypted in transit. Backups are access-controlled, and client data resides in isolated tenant environments.
Access control
Access inside the product is role-based (RBAC). Staff at your organization see only the properties they are assigned to. Internal DuePact employee access to customer data is restricted to operational necessity, granted under the principle of least privilege, and logged.
Authentication
Accounts are MFA-ready and administrators can require multi-factor authentication for their organization. Sessions use secure, signed tokens with short lifetimes. Enterprise single sign-on is available on request and is scoped in the customer agreement.
Model & data boundary
Client-specific PII is not used to train the global model. Client data resides in isolated tenant environments. Resident data sent to AI model providers for resolution packet generation is processed ephemerally and is not retained by those providers for model training under our provider agreements.
Integration boundary
DuePact supports a verified Entrata BlueStream Cloud workflow using bidirectional API read via the Entrata REST endpoint v1/endpoints/billing/ledger. DuePact runs nightly jobs to capture ledger_state, payment_history, and promise_to_pay data for Resolution Packet generation. Raw pipeline data is ephemeral and retained for 72 hours max per pipeline.
This proof verifies the Entrata ledger-read workflow for packet generation. DuePact does not claim official Entrata partnership, logo permission, write-back rights, or live integrations with AppFolio, Yardi, RealPage, or Buildium. Those systems are supported through CSV import and export.
Access profiles & data handling
The Resolution Packet view is restricted behind the Collections_Manager role profile. External parties cannot view raw ledger history outside the generated packet summary. Dormant accounts with no activity in the last six months route to Assistance Eligibility review rather than immediate dunning. Rule Set updates trigger packet re-validation for human review.
Audit logs
Audit logs record each human approval, edit, or override with timestamp and user ID. Logs are immutable and available to account administrators for the active subscription period.
Incident response
Suspected security incidents are triaged within 24 hours of detection. Affected customers are notified within 72 hours of confirmed impact, with a description of what occurred, the data involved, and the steps being taken.
Responsible disclosure
Researchers and customers can report suspected vulnerabilities to security@duepact.com. We acknowledge reports within 48 hours and work in good faith with reporters who avoid privacy violations, service disruption, and data exfiltration during testing.
Subprocessors
Subprocessors: AWS for hosting and SendGrid for internal notifications only. SendGrid is used to deliver account, billing, and security messages to your team — never to residents. A current subprocessor list is available for procurement review on request to security@duepact.com.