Security & Trust

Built for trust, by design

Your community's records are sensitive. CommunityVault protects them with role-based access, full audit history, and strict per-community data isolation.

Role-based access

Admins, board members, residents, and viewers each see only what they're allowed to. Board-only documents never appear in resident answers.

Activity history

Every action is logged — who did what, and when — for uploads, approvals, searches, and document access.

PDF records

Export tamper-evident summaries of every approval, meeting, and decision.

Secure document vault

Files are stored privately with visibility controls. Sensitive documents stay board-only or admin-only.

Per-community isolation

Each community's data is fully separated — one association's records are never exposed to another.

Exportable reports

Your data is yours, always exportable in standard formats. Trial customers can delete all data on request.

How we handle your data with AI

CommunityVault uses AI to make your records searchable, to summarize and categorize uploaded documents, and to answer board and resident questions. Here's what that means for your community's data.

What AI does with your documents
When you upload a document, we extract its text, convert it into a searchable index, and use it to generate summaries, suggest a category, and answer questions inside your community. Your original files stay in CommunityVault's secure storage — only the text needed to fulfill a request is sent to our AI provider.
Which AI providers we use
We use the OpenAI API for text extraction, search embeddings, and AI-generated answers. OpenAI processes this data only to return results to CommunityVault — it does not receive your account credentials or use it for advertising.
Your data is not used to train AI models
Per OpenAI's API data-usage policy, content sent through the API is not used to train or improve their models. API data may be retained by OpenAI for up to 30 days to monitor for abuse and misuse, after which it is deleted. We never sell your data, and we don't use your community's documents to train any model of our own.
Access & isolation
AI answers respect the same role-based permissions as the rest of the platform — board-only documents never surface in resident answers, and one community's data is never used to answer another's questions.
Your data stays yours
You can export your records at any time, and you can ask us to delete your community's documents and their AI index. Deleting a document also removes it from the searchable index.

Questions about how your data is processed? Email support@communityvault.ai.

How we handle your data

CommunityVault is built on modern, trusted infrastructure and applies security best practices at every layer. Here is exactly how your community's data is stored, protected, and kept private.

Where your data is hosted
CommunityVault runs on Vercel (application and edge delivery) and Supabase (database and file storage). Your data is stored in the US East region.
Encryption in transit and at rest
All data is encrypted in transit using TLS. Data at rest is encrypted by Supabase using AES-256 at the storage layer — your documents, member records, and board decisions are never stored in plain text.
Per-community isolation via Row-Level Security
Every database query is enforced by Supabase Row-Level Security (RLS) policies. This means one community's records cannot be read by another community's users — even if they share the same underlying database. Board-only documents are also filtered by role at the same level.
Email and notification provider
Transactional emails (invitations, status updates, request notifications) are sent via Resend. Emails include your community name and are sent only for product activity — we do not send marketing email on your behalf.
Your data is exportable and deletable
You can export reports, minutes, approvals, and member lists at any time. You can request deletion of your community's data — documents, member records, and AI indexes — and it will be permanently deleted within 30 days. We do not retain backups of deleted community data after deletion is processed.

Questions about hosting or data handling? Email support@communityvault.ai.