Skip to main content
Trust & compliance

Security & account protection

How we protect PropertyBin accounts and what you can do to stay safe. These practices support the Privacy Policy — they are not a guarantee against every threat.

Last updated: August 2026

HTTPS in transit MFA & passkeys Least privilege Responsible disclosure

Transport

Traffic between your browser and PropertyBin uses HTTPS / TLS.

  • Public pages and signed-in portals share the same encrypted transport.
  • Confirm the address bar shows propertybin.ca before entering credentials.

Accounts

Credentials are hashed. Optional MFA and passkeys reduce account takeover risk.

  • Passwords stored with one-way hashing, never plain text.
  • TOTP, email codes, backup codes, and WebAuthn where the device supports it.
  • Login, reset, and OTP endpoints are rate-limited.

Security settings

Sessions & cookies

You can change password and sign out from your account. Cookie categories live on the Cookies page.

  • Session cookies keep you signed in on a device you control.
  • Preference and analytics cookies are described in the Cookies notice.
  • Sign out on shared computers.

Cookies

Data access

Pro CRM, lockboxes, portfolio media, and marketing connections stay scoped to the owning account or organization.

  • Admin tools are restricted; secrets are not dumped into public error pages.
  • Signed-in users can export or request deletion from the Privacy hub.
  • We do not sell personal information to data brokers.

Privacy Policy

What we do not do

  • We do not ask for your password or MFA codes by unsolicited email, SMS, or chat.
  • We do not require consumers to pay to search listings or use core calculators.
  • We do not publish a vendor laundry list or claim “bank-grade” security.

What you should do

  • Use a unique password or a passkey; enable MFA here and on the inbox used for recovery.
  • Treat unexpected “verify your listing” or “wire deposit” messages as suspicious — confirm the domain is propertybin.ca.
  • Pros: treat CRM notes and lockbox codes as confidential; rotate shared codes when staff change.
  • Report impersonation to security@propertybin.ca and to your email provider.

Responsible disclosure

If you believe you found a vulnerability, email security@propertybin.ca with the URL or feature, steps to reproduce, likely impact, and a contact for follow-up.

Please do not access other users’ data, run destructive tests, or disrupt the service. Good-faith reports are acknowledged as capacity allows.

Account takeover on your account: change password, enable MFA, review connected social accounts, and contact support.

FAQ

Where do I turn on MFA?
Sign in, then open Account security. Authenticator apps, email codes, backup codes, and passkeys appear when your device supports them.
How do cookies relate to security?
Session cookies keep you signed in. Preference and measurement cookies are optional where the preference centre allows. See the Cookies page and Privacy Policy.
Do you guarantee no incidents?
No platform can. We describe practices in plain language and keep the Privacy Policy as the legal record of how personal information is handled.

Questions about security or privacy?

Use account settings for MFA. Use contact for account incidents. Use security@propertybin.ca for product vulnerabilities.