Effective date: 10 September 2026
This statement summarises Orchard's current security controls for customers and prospective customers. It is not a certification, penetration-test report, guarantee that an incident cannot occur, or a substitute for a Customer's own risk assessment.
Governance and responsibility
Synthetic Technology Ltd maintains administrative, technical and organisational measures proportionate to the property-management data handled by Orchard. Security concerns are triaged through notifications@orchardpms.com. Material incidents are recorded with ownership, severity, affected records, containment, notification decisions, remediation and post-incident review.
Identity and access
- administrator, manager and tenant roles with server-side authorisation checks;
- unique user accounts, hashed passwords, email verification and secure recovery;
- optional authenticator-app multi-factor authentication for every user role, single-use recovery codes and revocable 30-day remembered browsers;
- secure, HTTP-only, SameSite session cookies, session-ID regeneration and 30-minute authenticated inactivity expiry;
- CSRF protection for state-changing requests and re-authentication or confirmation for sensitive workflows; and
- audited exceptional administrative activation and MFA recovery, with separate account, verification and suspension states.
Application and transport security
Production traffic uses HTTPS. Orchard sets frame, content-type, referrer, permissions and transport-security headers where applicable. Database operations use parameterised queries in current application services and forms validate server-side. Abuse-sensitive public forms use invisible bot detection with server-side action and hostname validation, one-time challenge tokens, signed form-age checks, honeypots and rate limits to reduce automated abuse and replay. Public recovery endpoints also use generic responses to reduce account enumeration.
Orchard AI controls
Orchard AI is limited to authenticated manager accounts and uses fixed, parameterised, read-only data tools scoped to the requesting manager. It does not execute model-generated database queries or modify portfolio records. Requests exclude uploaded file contents, private manager notes and screening scores. Orchard limits request frequency, conversation context, tool calls, answer length, user credits and overall provider spend. Provider-side response storage is disabled, while content-free usage and error records support billing, security and reliability review.
Data, files and backups
IONOS hosts Orchard's production application, database and scheduled backups in the European Union. Provider backups are encrypted and access-controlled. Uploads are constrained by size, file extension and detected MIME type, stored with generated names, and served through permission checks. General upload forms prohibit identity documents and legally sensitive categories. IONOS provides infrastructure-level threat and malware protections; Orchard's controls do not represent that every uploaded document has received independent content certification.
Logging and monitoring
Orchard records authentication, verification, email dispatch, account administration, settings, public-page changes, data exports, selected document actions, billing and other security-relevant events. Audit records can include actor, role, event, entity, property context, outcome, IP address, user agent, session identifier, timestamp and before/after summaries. Authorised administrators can review the Security & Audit console and incident register.
Availability and recovery
Hosting, database and backup services are provided by IONOS. Orchard uses scheduled backups and restoration procedures intended to recover service after an incident. Planned maintenance is communicated where reasonably practicable. Unless an order form expressly says otherwise, provider availability targets are not an Orchard service-level guarantee.
Vulnerability and change management
Security updates are prioritised when identified, changes are reviewed in proportion to risk, dependencies are maintained, and access or credentials can be revoked during an incident. Independent assurance or certification evidence will be identified in this statement if obtained; Orchard does not claim SOC 2 or ISO 27001 certification.
Incident notification
Orchard assesses suspected personal-data breaches promptly. As processor, Orchard notifies the affected Customer without undue delay after becoming aware of a breach involving Customer Personal Data. As controller, Orchard reports a notifiable breach to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours, and informs affected people without undue delay where high risk requires it. The form and timing of notice depend on verified facts and applicable law.
Customer responsibilities and assurance requests
Customers must manage authorised users, remove obsolete access, secure their devices, avoid prohibited data, review exports and configure their own lawful retention. Reasonable security or audit enquiries may be sent to notifications@orchardpms.com. Contractual audit rights are set out in the Data Processing Addendum.