Trust
Security and hosting
Where your data is, how it's backed up and protected, and what could leave Quebec. This page only describes what is in place today.
In short
- Since September 29, 2026, Plexago has been hosted by Amazon Web Services (AWS), in Montréal.
- A verified backup every day; the last 14 are kept.
- Login required, two-factor authentication available, and everyone sees only what their role allows.
- Your tenants get into their portal with their lease's invitation code, with no password, and see only that lease there.
- AI, and the app's emails and texts, stay blocked until your privacy impact assessment (PIA) is recorded.
Hosting
Since September 29, 2026, the Plexago app (app.plexago.ca) has been running at Amazon Web Services, in its Canada (Central) region, in Montréal (ca-central-1). The database, your leases, your documents and your photos are kept there together, in the app's data folder.
The app runs in a container, under an account with no special privileges. The software's code is kept in a private repository that holds no customer data.
Backups
Every day, Plexago automatically backs up the database and the files, and keeps the last 14 backups. Each backup is reopened and compared with the original (integrity, row counts); every month, the most recent one is restored separately to check that it works. These backups are kept on the same server, in Montréal.
You can also export your lists and reports at any time, and an administrator can download all your data: Download the complete export (ZIP), in Privacy.
Login and access
- Login required. Online, Plexago's management screens never open without an account. A new installation only opens with a single-use code that only the people running the hosting can read.
- Passwords. Stored hashed (scrypt), never in plain text. After 5 failed attempts in 15 minutes, logging in to that account is suspended for 15 minutes.
- Two-factor authentication. On top of the password, a 6-digit code from the authenticator app on your phone, with backup codes. The codes are computed on the phone: no text messages, nothing leaves Quebec. Each person turns it on in SettingsAccount security; an administrator can require it for the whole management team.
- Roles. Each person has their own account and sees only what their role allows: a janitor, for example, only opens the requests for their buildings, and a tenant only their own lease.
- Sessions. Checked on every request: changing a password or a role closes open sessions. The login cookie is out of reach of page scripts.
- Access log. Each page viewed is recorded (person, page, IP address) so an incident can be investigated; the log is deleted after 12 months.
Tenant portal
Your tenants get into their portal with no password, using their lease's invitation code. That code opens that lease only, and nothing else in Plexago.
- The code. 16 letters and digits, specific to the lease. Attempts are limited, per IP address and overall: after a few wrong codes, you have to wait. The code stops working when the lease ends, and Revoke access, on the unit's page, replaces it right away, in the portal and in the app.
- The QR code. In the letter's QR code address, the code comes after the “#”: the browser never sends it as such to the server, and it appears in no log. The page removes it from the address bar and the history before sending it.
- The session. A signed cookie, out of reach of page scripts, valid for 30 days after the last visit and never beyond the end of the lease. Each page checks again that the lease is current and that its code hasn't been replaced.
- What can be seen. Only that lease: a receipt, a notice or a question from another lease answers as if it didn't exist. Co-tenants share the code, so their email addresses, phone numbers and addresses are partly hidden there. Management pages stay closed, even with a code.
- What is recorded. The visit, to the day: not the time, the IP address or the device. The portal's data stays on the Montréal server; as in the app, only an urgent request can alert your team by text, if you've turned texts on.
Protecting the app
- Each page only runs Plexago's own scripts, marked with a new token on every request (strict content security policy).
- Every action and every file download checks the person's rights, and database queries are always parameterized. Automated tests check this on every code change.
- An uploaded document is never displayed as a page: an HTML file or an unknown type is downloaded, and a photo is recognized by its actual content.
- On every code change, and again every Monday, automated checks run: security tests, a search for secret keys in the code, and known flaws in components.
- A light penetration test was done on September 27, 2026: a manual review of the entry points, and an automated scan (OWASP ZAP) repeated every week. It found no flaw that would let a tenant or a janitor read or change someone else's data. It isn't a professional test: a test by an outside firm is planned before welcoming customers beyond the pilot program.
What could leave Quebec
Your data stays in Montréal. Features that rely on a provider located outside Quebec stay blocked until your privacy impact assessment (PIA) is recorded in Plexago (PIA completed on), as Law 25 requires (s. 17):
- Artificial intelligence. Reading leases, invoices and uploaded documents relies on Claude, from Anthropic, a provider located in the United States. In Upload your information, AI is only used if you tick its box when sending, and the emails and phone numbers in spreadsheets are masked before sending. Each AI answer is checked again, field by field, before it enters your records. Processing happens in the United States; every page read is counted, without the file's name or content, and a monthly cap stops AI before anything is sent once it's reached.
- The emails and texts the app sends.
And you?
Plexago gives you the Law 25 tools: person in charge, PIA, retention periods, incident register, access requests. Compliance remains your business's responsibility: see the guide Setting up Law 25 in Plexago. A security question, or a problem to report? Write to us at support@plexago.ca.
Last updated: September 30, 2026.