Help center
Security & compliance

Security and your data

Turn on two-factor authentication, manage sessions and backup codes, export your data, and review the audit trail.
Workflow at a glance
1
Two-factor authentication
2
Backup codes and sessions
3
Exporting your data
4
The audit trail

Two-factor authentication

Under Settings → Security you can register a second factor: an authenticator app (1Password, Authy, Google Authenticator, or similar) using a scanned or pasted setup key, or an SMS number. It's strongly recommended for any account that collects rent or holds tenant data.
One honest caveat: step-up enforcement is still rolling out, so a registered factor isn't yet demanded at every sign-in. Until it is, treat a strong, unique password as your primary protection and keep 2FA registered as the second layer.
1
Go to Settings → Security.
2
Choose "Add authenticator app" (or enter a phone number for SMS).
3
Scan the QR code or paste the setup key into your authenticator app.
4
Enter the 6-digit code it generates to verify and enable.

Backup codes and sessions

Once you have a verified factor, generate single-use backup codes and store them somewhere safe (a password manager) — they're your way back in if you lose your authenticator. You can download or copy them, and regenerating invalidates any old unused codes.
The Security screen also lets you sign out of every device at once (useful if a device is lost or stolen) and shows a login history of recent activity with browser, OS, and IP. If anything looks unfamiliar, change your password and confirm 2FA is on.

Exporting your data

Under Settings → Account, "Your data" provides a bounded JSON personal-data export of supported records such as profile, leases, payments, messages, and work orders. A recent high-assurance sign-in and documented row limits apply; documents are represented by metadata rather than every stored file.

The audit trail

Every agent action and every policy change is recorded in a tamper-evident, hash-chained audit log, viewable as one chronological timeline you can filter by actor and date. From it you can export a CSV for compliance reviews (on the web app) and produce a Decision Integrity Certificate that attests the chain hasn't been altered. Separately, the agent activity feed shows a plain-language "why" for each autonomous decision, with undo where the action was reversible.
Editorial ownership
Written and maintained by the Aptoria editorial team
Editorial method reviewed July 28, 2026. Aptoria reviews scope, source fit, examples, limitations, links, and publication gates. This record does not claim attorney, CPA, lender, appraiser, or other independent professional sign-off.
Professional review is not claimed. Verify current law, tax treatment, loan terms, valuation inputs, and property-specific facts with the appropriate qualified professional before acting.
Didn't answer your question?
Email support@aptoria.ai with the relevant record and what you already tried. Response timing depends on the request and current support coverage.
Back to Help center