Skip to content

Trust

DuePact recommends. You decide.

Every notice, payment plan, fee, escalation, and resident communication requires human approval. Below: verified operating proof, the approval boundary in detail, security posture, data and model boundary, and subprocessors.

Verified operating proof

14,000+

Units under packet review at a Tier 1 REIT

15 min → 45 sec

Packet assembly per account, Q2 2026

65%

Less context switching reported by staff

100%

Human review before any action

Anonymized operator results measured against the operator's own workflow records following production go-live on February 15, 2026. Customer name and logo are withheld at their request.

The approval boundary

What DuePact does — and what it never does.

  • Reconciles ledger and flags discrepancies
    Sends notices to residents
  • Checks configured local rules and fee caps
    Provides legal advice
  • Drafts recommended action with reasoning
    Takes autonomous action
  • Drafts payment-plan options from templates
    Processes payments
  • Surfaces assistance eligibility
    Contacts residents on your behalf
  • Logs every recommendation, edit, and approval
    Files legal actions or makes adverse decisions

Security posture

Practices for sensitive financial and resident data.

  • EncryptionEncryption in transit for all application traffic
  • AccessRole-based access control with MFA-ready account controls
  • ApprovalApproval and override logs on every packet action
  • AuditImmutable approval, edit, and override logs
  • DisclosureResponsible disclosure program at security@duepact.com

Data & model boundary

Your data stays yours. Models do not learn from it.

  • TenancyEach customer's data in an isolated tenant environment
  • Model useClient PII is not used to train DuePact's global model
  • ResidentsResident data is processed ephemerally for packet generation
  • RetentionDefault 7 years, configurable per client agreement
  • DeletionCustomer-initiated deletion via security@duepact.com

Security practices

DuePact uses security practices appropriate for sensitive resident ledger workflows: encryption in transit, role-based access, MFA-ready account controls, approval and override logs, and human-reviewed packet actions. Formal certification claims should only appear after the current report type, date, scope, and public badge permissions are supplied.

Verified integration workflow

DuePact supports a verified Entrata BlueStream Cloud workflow using bidirectional API read via the Entrata REST endpoint v1/endpoints/billing/ledger. DuePact runs nightly jobs to capture ledger_state, payment_history, and promise_to_pay data for Resolution Packet generation. Raw pipeline data is ephemeral and retained for 72 hours max per pipeline.

This proof verifies the Entrata ledger-read workflow for packet generation. Do not claim official Entrata partnership, logo permission, write-back rights, or live integrations with AppFolio, Yardi, RealPage, or Buildium unless separate proof is supplied. All other systems are supported through CSV import and export.

Access control and data handling

The Resolution Packet view is restricted behind the Collections_Manager role profile. External parties cannot view raw ledger history outside the generated packet summary. Dormant accounts with no activity in the last six months route to Assistance Eligibility review rather than immediate dunning. Rule Set updates trigger packet re-validation for human review.

Subprocessors

  • AWSCloud hosting (US regions)
  • SendGridTransactional notifications to your staff only

Need a security review or DPA?

Security documentation and our standard DPA are available on request for procurement review.