Security & data handling
Property and commercial real estate operations run on sensitive records — leases, tenant details, compliance evidence and financial reporting. This page sets out how Almas works with that data during an engagement, in plain terms your technology and risk teams can review.
Current practices
How we work with your data
We build inside your systems. Almas does not retain client operational data outside active project work — no shadow copies of your lease files, tenant records or maintenance history are kept once an engagement ends.
Hosting
We deploy where you need it. Solutions can run inside your own environment, on your preferred cloud, or on a secure isolated cloud service. We commonly work with Microsoft Azure, Amazon Web Services (AWS) and Google Cloud Platform (GCP), and will recommend the option that fits your security, residency and operational requirements.
Access
We request the minimum access needed to deliver the work, granted for the duration of the engagement and revoked at the end. Access is named and traceable — never shared generic accounts where your systems support alternatives.
Confidentiality
An NDA is available on request before any workflow review, document sample or system walkthrough. Sample documents used during discovery are returned or deleted once the review is complete.
Shared responsibility
Security in a bespoke build is shared. This is the split we work to, and we confirm it in writing at the start of every engagement.
Almas
Your organisation
Reporting a concern
If you believe you have found a security issue in something we have built, or you have a question about how your data is handled, contact us directly. We aim to acknowledge every report within one working day.
hello@almassoftware.comAlmas Software Systems — Southampton, United Kingdom
Request a security review
We'll answer your security questions and provide the supplier information your risk team needs as part of contracting.
Book a security review