Skip to content
Our Stairwell
Overview
Features
All featuresExplore the shared workspaceMeetings and governanceKeep agendas, papers, attendance, proxies, minutes, decisions, and company records connected.Building recordsTrack works, quotes, certificates, insurance, assets, contractors, and the evidence behind each decision.Service charge recordsConnect demands, payments, credits, bills, funds, bank activity, reports, and unit ledgers.Document librarySearch file contents, filter by source, follow documents back to their records, and share evidence with control.Resident communicationPublish announcements, run discussions and polls, coordinate dates, and keep residents pointed to the right record.Resident accessConnect residents to units and roles while keeping finance, governance, and sensitive records appropriately controlled.Setup and prioritiesUse guided setup, dashboard priorities, invitations, notifications, controlled sharing, and exports to keep work moving.
How it worksPricingContactSupport
Sign in
Start free trial
Menu
OverviewFeaturesHow it worksPricingContactSupportSign inStart free trial

Legal and privacy

Security Measures Schedule

Pre-release draft ยท Version 2026-09-05

Technical and organisational measures used to protect customer data in Our Stairwell.

Legal and privacy
Privacy noticeCookies & storageSubscription termsData processingAcceptable useSupport & service levelsSubprocessorsSecurity measures

These documents are being prepared for launch. Our Stairwell Ltd has not yet been incorporated. Customer subscriptions will open only after incorporation and completion of the supplier details and launch terms. This draft does not offer a subscription from an existing limited company.

This schedule forms part of the Data Processing Agreement. The measures are risk-based and may evolve, provided the overall protection of Customer Personal Data is not materially reduced during a subscription.

1. Security governance

  • Named responsibility for production security, privacy requests and incident coordination.
  • Documented production-change, access, backup, incident and account-lifecycle procedures.
  • Confidentiality obligations for people with access to Customer Personal Data.
  • Periodic review of security risks, controls, providers and retention arrangements.
  • Security reports accepted at [email protected].

2. Identity and access control

  • Central authentication through Keycloak using standards-based OpenID Connect and short-lived bearer tokens.
  • Passwords are handled by the identity service and are not stored in the application database.
  • Association isolation, role-based permissions and record-level ownership checks are enforced in the application and API.
  • Administrative access is restricted to authorised operators; elevated and break-glass actions are separately controlled and audited.
  • Access is reviewed and removed when no longer needed. Customer administrators can manage user roles and permissions within their workspace.
  • Multi-factor authentication is used for production provider and privileged operator accounts where the provider supports it.

3. Network and transport security

  • Public production traffic is encrypted with HTTPS/TLS; plaintext public access is redirected or blocked.
  • Cloudflare edge, tunnel, web-application controls and rate limiting protect public entry points.
  • Databases, object storage, search, authentication and support components are not exposed as unrestricted public services.
  • Cross-origin API access is limited to configured application origins and the API uses explicit bearer authentication rather than browser session cookies.
  • Forwarded client-IP headers are accepted only from configured trusted proxy networks.

4. Data and secret protection

  • Production secrets are kept outside source control in a dedicated secret-management service and injected only into authorised workloads.
  • Sensitive integration tokens are encrypted before database storage where the integration requires recoverable credentials.
  • Off-site and lifecycle archives are encrypted, access-restricted and separated from ordinary application use.
  • Public object access uses scoped, time-limited URLs rather than making the storage bucket public.
  • Application responses and error telemetry are configured to avoid stack traces, secrets and default personal-data capture in production.
  • Data minimisation, retention limits and secure deletion are applied according to the Agreement and operational retention schedule.

5. Application security

  • Server-side authentication and authorisation apply to non-public API routes; public routes have purpose-specific validation, signatures, rate controls or expiring tokens.
  • Inputs are length-limited and validated. File uploads are subject to type, size and content-handling controls.
  • Customer-provided rich text is sanitised before display and download paths use generated identifiers and scoped access checks.
  • Payment bank details are entered directly into GoCardless's hosted verification flow; the Service retains limited mandate and account descriptors rather than complete bank credentials.
  • Dependencies and container images are reviewed for known vulnerabilities and security updates are prioritised according to risk.
  • Production changes are version-controlled, reviewed, deployed through controlled workflows and capable of rollback.

6. Logging, audit and detection

  • Requests receive a correlation identifier used across application logs and selected audit records.
  • Sensitive operations and break-glass activity record the actor, association, action, target, time and relevant request evidence.
  • Operational logs, error monitoring and availability checks are access-restricted and retained for defined periods.
  • Alerts cover service health, delivery failures, resource pressure and backup or security conditions appropriate to the production environment.
  • Logs are designed not to contain passwords, full authentication tokens or complete payment credentials.

7. Availability, backup and recovery

  • Production data and object storage are backed up to a logically separate, access-restricted location.
  • Backups use defined retention and integrity controls and are subject to periodic restoration tests.
  • Service components have documented restart, redeploy and rollback procedures.
  • Capacity, disk use and core endpoint availability are monitored so intervention can occur before foreseeable exhaustion.
  • Recovery priorities take account of the confidentiality, integrity and availability needs of resident and financial records.

8. Incident management

  • Security events are triaged, contained, investigated, remediated and documented using an incident process.
  • Evidence is preserved proportionately and access credentials are rotated where compromise is suspected.
  • Affected Customers receive breach information under the notification commitments in the DPA.
  • Material incidents receive a post-incident review and appropriate corrective actions.

9. Provider and personnel controls

  • Subprocessors are assessed for their role, security commitments, processing location and data-protection terms before use.
  • Provider access is limited by contract and technical controls and reviewed when the provider or feature changes.
  • Physical data-centre security is inherited from vetted hosting and storage providers.
  • Personnel use individual accounts, least-privilege access and secure credential storage; shared production credentials are prohibited.

10. Customer-controlled safeguards

Customer is responsible for choosing appropriate users and permissions, protecting its devices and accounts, reviewing access when roles change, minimising sensitive uploads, validating exports and notifying Supplier promptly of suspected misuse. Supplier's measures do not make Customer's configuration or content lawful by themselves.

11. Assurance and scope

This schedule describes contractual controls; it is not a claim that Our Stairwell holds an ISO 27001, SOC 2, Cyber Essentials or other certification unless Supplier separately provides current written evidence of that certification. Customer may request reasonable security information under the audit provisions of the DPA.

Our Stairwell

Block management software for UK resident-led buildings.

Explore
FeaturesPricingHow it worksContactSupportLegal