Security

How Pangoni protects your data and your money

This page describes how the system is built, what we can confirm in writing, and what we will not claim without evidence. If you are running a security review, start here and then send us your questionnaire.

Money

Pangoni never holds your money

Rent moves directly from the tenant to your own M-Pesa Paybill or Till. It does not pass through a Pangoni account, a pooled wallet, or a settlement float. Pangoni reads the transaction, matches it to the right tenant and unit, issues the receipt and updates the balance.

This matters more than any certificate on this page. The single largest financial risk in property management software — a vendor holding client funds — does not exist here, because the funds never arrive with us.

  • Tenant pays your Paybill or Till
  • Pangoni reads and reconciles the payment
  • No pooled wallet, float, or settlement delay
  • Your Paybill credentials stay yours
Data

How your data is stored and protected

Encrypted in transit and at rest

Data is encrypted in transit and at rest using AES-256. That covers tenant records, identity documents and KRA PINs held in your account.

Automated daily backups

Backups run automatically with multiple redundancies, so recovery does not depend on anyone remembering to take one.

Document storage

Leases, tenant IDs and compliance documents are stored with version history, so you can retrieve what was filed and when.

Access

Who can see what, inside your account

Most real incidents in property management are not break-ins. They are a caretaker seeing financial data, a departed agent retaining access, or a dispute with no record of who changed what. Access control is structural rather than a matter of trust.

See the organisational controls →

  • Role-based permissions Agents, accountants and caretakers get only the access their job needs.
  • Owner access is read-only and scoped Landlord clients see their own properties and nothing else.
  • Activity log Who did what and when, so accountability survives staff turnover.
  • Workspace separation Branches and trading names are separated inside one account.
  • OAuth2 on the API API access is token-based and scoped, not shared credentials.
Straight answers

What we will and will not claim

Security pages are usually a list of badges. If you are evaluating vendors seriously, what you actually need is to know which claims come with evidence behind them.

Ask us and we will answer in writing

Where your data is hosted and in which jurisdiction. Backup retention and restore testing. Who inside Pangoni can access production data and under what controls. Our incident and breach notification process. Sub-processors we rely on. Deletion and export on termination.

We complete security questionnaires

Send yours and we will complete it rather than pointing you at a badge wall. If the honest answer to a question is “not yet”, that is the answer you will get, along with what we do instead.

Shared responsibility

What stays on your side

No platform can protect an account against its own credentials being shared. The controls that matter most in practice are ones you operate:

Review access regularly

Remove agents and caretakers when they leave. The activity log shows who is actually using the account.

Protect your Paybill

Treat the Safaricom portal with the same care as a bank login, and keep the list of people who can access it short.

Use strong, unique passwords

Do not reuse a password between Pangoni, your email and your Safaricom portal.

FAQ

Security questions we are asked

No. Rent moves directly from the tenant to your own M-Pesa Paybill or Till. It does not pass through a Pangoni account, a pooled wallet or a settlement float. Pangoni reads the transaction, matches it to the right tenant and unit, issues the receipt and updates the balance.

Yes. Data is encrypted in transit and at rest using AES-256, including identity documents and KRA PINs held in your account.

Backups run automatically on a daily schedule with multiple redundancies. For retention periods and restore testing, contact us and we will confirm the current position in writing.

Yes. Permissions are role-based: agents, accountants and caretakers get only the access their job needs, and landlord clients get read-only visibility of their own properties. Every action is written to an activity log showing who did what and when.

Contact us and we will confirm the current hosting arrangement and jurisdiction in writing as part of your security review. We would rather give you an accurate answer for your specific review than a general statement on a web page.

Ask us as part of your security review and we will tell you exactly what we do and do not hold, rather than listing badges. Where the answer is not yet, we will describe the controls we operate instead.

Yes. Send it to the team and we will complete it. If a question has an answer we cannot evidence, we will say so rather than working around it.

Your records remain exportable, and deletion and export terms on termination are confirmed as part of your agreement. Contact us for the current terms.

Security review

Send us your questionnaire

Tell us what your review requires and who needs to sign it off. We will complete it and flag anything we cannot yet evidence rather than working around the question.