How Pangoni protects your data and your money
This page describes how the system is built, what we can confirm in writing, and what we will not claim without evidence. If you are running a security review, start here and then send us your questionnaire.
Pangoni never holds your money
Rent moves directly from the tenant to your own M-Pesa Paybill or Till. It does not pass through a Pangoni account, a pooled wallet, or a settlement float. Pangoni reads the transaction, matches it to the right tenant and unit, issues the receipt and updates the balance.
This matters more than any certificate on this page. The single largest financial risk in property management software — a vendor holding client funds — does not exist here, because the funds never arrive with us.
-
Tenant pays your Paybill or Till
-
Pangoni reads and reconciles the payment
-
No pooled wallet, float, or settlement delay
-
Your Paybill credentials stay yours
How your data is stored and protected
Encrypted in transit and at rest
Data is encrypted in transit and at rest using AES-256. That covers tenant records, identity documents and KRA PINs held in your account.
Automated daily backups
Backups run automatically with multiple redundancies, so recovery does not depend on anyone remembering to take one.
Document storage
Leases, tenant IDs and compliance documents are stored with version history, so you can retrieve what was filed and when.
Who can see what, inside your account
Most real incidents in property management are not break-ins. They are a caretaker seeing financial data, a departed agent retaining access, or a dispute with no record of who changed what. Access control is structural rather than a matter of trust.
-
Role-based permissions Agents, accountants and caretakers get only the access their job needs.
-
Owner access is read-only and scoped Landlord clients see their own properties and nothing else.
-
Activity log Who did what and when, so accountability survives staff turnover.
-
Workspace separation Branches and trading names are separated inside one account.
-
OAuth2 on the API API access is token-based and scoped, not shared credentials.
What we will and will not claim
Security pages are usually a list of badges. If you are evaluating vendors seriously, what you actually need is to know which claims come with evidence behind them.
Ask us and we will answer in writing
Where your data is hosted and in which jurisdiction. Backup retention and restore testing. Who inside Pangoni can access production data and under what controls. Our incident and breach notification process. Sub-processors we rely on. Deletion and export on termination.
We complete security questionnaires
Send yours and we will complete it rather than pointing you at a badge wall. If the honest answer to a question is “not yet”, that is the answer you will get, along with what we do instead.
What stays on your side
No platform can protect an account against its own credentials being shared. The controls that matter most in practice are ones you operate:
Review access regularly
Remove agents and caretakers when they leave. The activity log shows who is actually using the account.
Protect your Paybill
Treat the Safaricom portal with the same care as a bank login, and keep the list of people who can access it short.
Use strong, unique passwords
Do not reuse a password between Pangoni, your email and your Safaricom portal.
Security questions we are asked
No. Rent moves directly from the tenant to your own M-Pesa Paybill or Till. It does not pass through a Pangoni account, a pooled wallet or a settlement float. Pangoni reads the transaction, matches it to the right tenant and unit, issues the receipt and updates the balance.
Yes. Data is encrypted in transit and at rest using AES-256, including identity documents and KRA PINs held in your account.
Backups run automatically on a daily schedule with multiple redundancies. For retention periods and restore testing, contact us and we will confirm the current position in writing.
Yes. Permissions are role-based: agents, accountants and caretakers get only the access their job needs, and landlord clients get read-only visibility of their own properties. Every action is written to an activity log showing who did what and when.
Contact us and we will confirm the current hosting arrangement and jurisdiction in writing as part of your security review. We would rather give you an accurate answer for your specific review than a general statement on a web page.
Ask us as part of your security review and we will tell you exactly what we do and do not hold, rather than listing badges. Where the answer is not yet, we will describe the controls we operate instead.
Yes. Send it to the team and we will complete it. If a question has an answer we cannot evidence, we will say so rather than working around it.
Your records remain exportable, and deletion and export terms on termination are confirmed as part of your agreement. Contact us for the current terms.
Send us your questionnaire
Tell us what your review requires and who needs to sign it off. We will complete it and flag anything we cannot yet evidence rather than working around the question.