Security at LeasePilot HQ

You're storing tenant applications, signed leases, and payment activity in LeasePilot HQ — here's how that data is actually handled.

Encrypted in transit

All traffic to and from LeasePilot HQ is encrypted over HTTPS/TLS, including the app, API, and tenant/vendor portals.

Passwords never stored in plain text

Account passwords are hashed with bcrypt before storage — we don't store or have access to your plain-text password.

Payments handled by Stripe

Online rent payments are processed through Stripe. LeasePilot HQ does not store your bank account or card details directly.

Screening handled by a licensed provider

Tenant credit and background checks are run through a licensed third-party screening provider — applicants submit sensitive information directly to that provider, not stored by LeasePilot HQ.

Documents stored on Amazon S3

Uploaded leases, screening reports, and property documents are stored using Amazon S3, a widely-used cloud storage provider.

Content Security Policy & security headers

The application enforces a Content Security Policy and standard security headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy) to reduce the risk of common web attacks like cross-site scripting.

Reporting a security issue

If you believe you've found a security vulnerability in LeasePilot HQ, please report it responsibly to [email protected] rather than disclosing it publicly. See our security.txt file for the current contact and reporting details.

Read our full Privacy Policy

For the complete details on what data we collect and how it's used, see our Terms of Service & Privacy Policy.

View Privacy Policy