Skip to content

Security

How we protect your project and broker data

What the platform does today, stated plainly — including what we do not have yet.

Reviewed and updated October 8, 2026

Encryption

  • All traffic to the apps uses HTTPS; plain HTTP is redirected, and browsers are told to use HTTPS only (HSTS).
  • Google Cloud encrypts stored data by default.
  • Integration credentials and stored secrets are additionally encrypted by Nogbase with AES-256-GCM.

Accounts and sign-in

  • Passwords are stored as bcrypt hashes, never in readable form.
  • Sessions use short-lived access tokens and refresh tokens that rotate on every use; reusing an old refresh token ends the session.

Who can see what

  • Every workspace’s records are separated in the backend: each query is limited to the workspace it belongs to.
  • Within a workspace, owners, admins and members get the permissions you assign.
  • Brokers see your private unit inventory only through the listings you share with them — the brokerages, units, time window and commission terms you choose.
  • Projects in the shared property catalog are visible to signed-in developer and broker workspaces unless you mark them private.

Change history

Changes to records are kept in an append-only history: what changed, the values before and after, and who made the change. EOIs, payments, configuration and file access have their own logs.

Backups and recovery

  • The database is backed up daily with point-in-time recovery.
  • File storage keeps versions of every file, with a daily copy to a separate backup bucket kept for 30 days.
  • Restoring production from backup was last tested in August 2026.

How we build

Code changes are scanned automatically for vulnerabilities (CodeQL), for leaked secrets (gitleaks) and for known issues in dependencies (dependency review and Dependabot).

Payments

Nogbase does not store card details or hold buyer or commission funds.

AI assistants

The Nogbase connector for ChatGPT, Claude and Codex is read-only and limited to what your account can already see. Access tokens expire after an hour and the connection ends after 30 days without use; you can disconnect at any time. Our request logs never contain your questions or the data returned.

Certifications

Nogbase does not hold SOC 2 or ISO 27001 certification today. If your procurement process needs a security questionnaire, we will answer it.

Report a security issue

Email support@nogbase.ae with the details and how to reproduce it. Please don’t access other customers’ data or disrupt the service while testing. Our security.txt lists the same contact. How we handle personal data is in the privacy policy.