Security

Security your management company can stand behind.

You're trusting Ask Redline with residents' questions, your governing documents and the day-to-day operation of every community you run. Here's how that data is kept separated, access is controlled, and every action stays accountable.

Hard multi-tenant isolation

Every community's conversations, documents and records live behind strict tenant boundaries. A person only ever reaches the communities they belong to, enforced in the backend on every request, not just hidden in the interface.

Role-based access & permissions

A clear hierarchy, resident, board member, community manager, company admin and platform staff, plus custom roles you define. Enabled modules and approvals decide exactly what each person can see and do. The manager Copilot is scoped to the selected community, never a free-roaming query engine.

Audit logging

Sensitive actions are recorded with who, what and when. Managers and admins can review the activity log, so there's always an accountable trail behind a change, an approval or a message that went out.

Messaging compliance

TCPA-aware consent capture, A2P 10DLC brand and campaign registration for text, honored opt-outs (STOP/HELP) and quiet hours. Residents opt in before they're messaged, and every broadcast respects that consent.

Safe outbound fetching

When Redline reads a community's website or a monitored page, requests are guarded against SSRF and DNS-rebinding, with bounded reads. Site traffic analytics are paginated and searchable without ever exposing raw IP or user-agent data.

Reliable background operations

Emergency paging and scheduled loops run isolated from live web traffic, with worker supervision, a leader lease and atomic paging claims. The concierge answering residents can't be starved by a background job, and vice-versa.

AI safety & grounding

Answers are grounded in each community's own documents, rules and contacts. When something needs a person, the concierge hands off to a human. Copilot actions are confirmed and community-scoped, nothing acts on your behalf without an owner and an approval.

Encryption & least-privilege access

Traffic is encrypted in transit, and internal access follows least-privilege, people and systems get only the access the task in front of them requires, and nothing more. Your community's data stays yours; it's never sold or repurposed for advertising.

Want the details for your review?

We're glad to walk your team through isolation, permissions, data handling and messaging compliance, and answer a security questionnaire as part of your evaluation.