Security
Last updated August 2026
SmartLord holds your portfolio's financial records and your tenants' personal details. Here is how we keep them safe — in plain terms.
Where your data lives
Your data is stored in managed PostgreSQL hosted in a UK region (London). In normal operation it stays within the UK/EU.
One workspace can never see another's
Every workspace is isolated at the database level with row-level security. That isolation is enforced by the database itself, not just the application — so one account cannot read another's properties, tenants or figures, even in the event of an application bug.
Encryption
All traffic between your browser and SmartLord is encrypted in transit with TLS, and your data is encrypted at rest by our infrastructure provider.
Payments
Card payments are handled entirely by Stripe. Your card details are entered on Stripe's own secure checkout and never touch SmartLord's servers.
Access and backups
Access is authenticated per user and scoped to your workspace by role (owner, staff or accountant). The database is backed up automatically by our provider. You can export your own records to CSV at any time from inside the app.
The providers we rely on
We keep our supplier list short and use established providers, each contracted to process data only on our instructions:
- Supabase — managed database, authentication and file storage (UK region).
- Stripe — subscription payments and card handling.
- Vercel — application hosting and delivery.
- Resend — transactional email (the reminders and digests you switch on).
Found a problem?
If you believe you've found a security issue, please email isaac@corn.blue and we'll respond quickly. See also our Privacy notice.