GateConet Payment & Security
Trust & Security

Security & Trust

Last updated: August 2, 2026

1. Overview

GateConet is designed to help estates control access and organise sensitive records. The final production security commitments depend on the hosting, payment, messaging, and operational providers selected by the business.

2. Access control

Administrator, resident, finance, and security workflows are separated so each person can access the tools relevant to their role. Estate operators are responsible for assigning appropriate roles, removing access when a person leaves, and keeping account details current.

3. Visitor and gate records

Visitor passes, verification, and gate activity can create a record of expected and completed visits. Estates should define their own approval, identification, vehicle, retention, and incident-escalation procedures for security personnel.

4. Application security

The application includes prepared database statements, password hashing, CSRF protection, escaped output, role-based route guards, secure session settings, and protected storage paths. These controls support security but do not remove the need for secure hosting, patching, monitoring, backups, and operational procedures.

5. Data handling

Resident, payment, maintenance, facility, visitor, vehicle, message, and document records should be accessed only by authorised users and retained only for a justified business or legal purpose. The applicable collection and use details are described in the Privacy Policy.

6. Providers and subprocessors

Payment gateways, email, SMS, WhatsApp, hosting, analytics, and other service providers may process information when those services are enabled. The production provider list, hosting location, encryption configuration, backup frequency, and retention periods must be confirmed and published before launch.

7. Report a security concern

Please do not test or exploit the service without permission. Report suspected vulnerabilities, exposed information, or account-security issues promptly through the contact details below, including enough detail for the team to reproduce the concern safely.

8. Contact us

For security questions or reports, please contact us or email [email protected].

Production note: this page is a starting statement. Hosting, encryption at rest, backup, incident response, subprocessors, data retention, and any compliance certifications need to be confirmed before launch.