Security
How we protect the information we hold
Augustine Realty maintains a documented information security programme covering the public site, the resident and owner portals, and our internal financial tooling. Both policies below are current and in force.
Version 1.0: 2 August 2026
Information Security Policy
How we identify, mitigate and monitor information security risks: risk management, data classification, encryption and key management, vendor and sub-processor review, secure development, logging and monitoring, backup and continuity, and incident response.
Information Security Policy (PDF)
Access Control Policy
Who may reach our systems and data, and on what basis: our zero-trust access architecture, role-based access control, joiner/mover/leaver procedure, quarterly access reviews and audits, non-human authentication using OAuth 2.0 and TLS, and credential lifecycle management.
Vulnerability Management Policy
How we find and fix security defects: continuous dependency scanning, endpoint protection, end-of-life software monitoring, and our remediation SLA: 24 hours for critical, 7 days for high.
Vulnerability Management Policy (PDF)
Data Retention and Disposal Policy
How long we keep each category of data, the legal or business basis for each period, how deletion requests are handled, and how data is destroyed when the period ends.
Data Retention and Disposal Policy (PDF)
Security contact
Austin Riley Clough, Chief Executive Officer: augustinerealtycompany@gmail.com. This mailbox is monitored and is the address for security questions, diligence requests, and vulnerability reports.
Reporting a vulnerability
If you believe you have found a security problem in anything we run, email help@augustineportal.com with enough detail to reproduce it. We will acknowledge it and tell you what we did. Please do not access, modify or retain anyone else's data while investigating.
