Association control
Customer records are used to provide the service, not sold or repurposed for unrelated advertising.
SECURITY & DATA OWNERSHIP
HOAvenue is designed so operational data remains controlled, permissioned, auditable, and exportable. This page distinguishes verified safeguards from the controls still being completed.
CURRENT SAFEGUARDS
Association-, role-, and property-scoped portal access
Password hashing, login throttling, and 14-character minimums
Self-service password recovery with expiring single-use links
Optional authenticator-app verification and one-time recovery codes
Session invalidation after password changes
CSRF protection, strict secure cookies, and browser security policy
Prepared database statements
Private document storage outside the public website
Restricted file types, randomized names, and size limits
Dated audit records for material activity
Deployment backup and automatic rollback protection
NEXT HARDENING MILESTONES
Verified, expiring account invitations
Active-session and recognized-device controls
Automated authorization and tenant-isolation testing
Encrypted off-site backup with scheduled restore exercises
Structured security monitoring and incident runbook
Published retention, deletion, and export schedules
DATA PRINCIPLES
Customer records are used to provide the service, not sold or repurposed for unrelated advertising.
Users receive access according to their association, role, and assigned property records.
Each customer agreement will define export format, retention period, and account closeout.
The production website, portal, database, deployment system, and operating records run independently on HostGator.
BOARD DUE DILIGENCE
Founding-community proposals include the hosting model, access roles, backup approach, known limitations, data-handling terms, support path, and export process. Security claims expand only after the corresponding controls are verified.
REVIEW THE CURRENT SYSTEM