Security Overview
The MRI Qube integration implements enterprise-grade security measures to protect your data throughout the synchronisation process.All security measures comply with UK GDPR, the Data Protection Act 2018, and RICS best practices.
Credential Security
Vault Encryption
API credentials are encrypted at rest using Supabase Vault:- Encryption: AES-256-GCM
- Key Management: Automatic key rotation
- Access: Row-level security policies
Credential Rotation
The system tracks credential age and alerts directors when rotation is due:| Age | Status | Action |
|---|---|---|
| 0-60 days | 🟢 Current | No action needed |
| 60-90 days | 🟡 Due Soon | Plan rotation |
| 90+ days | 🔴 Overdue | Rotate immediately |
Data Protection
Data in Transit
- All API calls use TLS 1.3 encryption
- Certificate pinning for the Vaultre API
- No sensitive data in URL parameters
Data at Rest
- Database encrypted with AES-256
- Backups encrypted with separate keys
- Point-in-time recovery enabled
Data Minimisation
Only essential data is synchronised:Synced Data
Synced Data
- Property and unit details
- Tenancy information
- Financial transactions
- Contact business details
- Maintenance records
- Compliance documents
Not Synced
Not Synced
- Personal bank account numbers
- National Insurance numbers
- Passport/ID copies
- Medical information
- Criminal records
Access Control
Role-Based Access
Only authorised users can configure or access MRI integration:| Role | Permissions |
|---|---|
| Building Director | Full access to configuration and data |
| Property Manager | View sync status, trigger manual syncs |
| Homeowner | View own synced data only |
| Super Admin | Full access across all buildings |
Row-Level Security
Supabase RLS policies ensure users only access their authorised buildings:Audit Logging
What’s Logged
All integration activities are logged for compliance:- Credential access and changes
- Sync operations (start, complete, errors)
- Data modifications from sync
- Configuration changes
- Manual overrides
Log Retention
| Log Type | Retention |
|---|---|
| Sync logs | 90 days |
| Audit logs | 7 years |
| Error logs | 1 year |
Compliance
GDPR Compliance
Data processing agreement with MRI Software/Vaultre
Standard Contractual Clauses for Australia data transfer
Data subject access request support
Right to erasure implementation
Data Processing Agreement
MRI Qube/Vaultre operates from Australia. We have:- DPA in place with MRI Software
- SCCs (Standard Contractual Clauses) for international transfer
- Data breach notification procedures agreed
Security Checklist
Weekly
- Review sync error logs
- Check for failed authentications
Monthly
- Audit user access permissions
- Review credential access logs
- Check sync performance metrics
Quarterly
- Rotate MRI credentials
- Security assessment
- Review DPA with MRI
Incident Response
If you suspect a security issue:- Immediately disable the MRI integration in Settings
- Contact security@manage.management
- Document what you observed
- Preserve any relevant logs