Lettright
Products Platform Security Customer login Book a demo
Security & Trust

Keeping your data safe

Last reviewed: 13 July 2026

Lettright holds exactly the kind of information that has to be looked after properly — your tenants', landlords' and applicants' personal data, and the details of every property you manage. This page explains, in plain terms, the measures we take to protect it. We follow a defence-in-depth approach: several independent layers of protection, designed so that no single failure exposes your data.

At a glance

  • Hosted in the UK on ISO 27001-certified infrastructure
  • Encrypted in transit (HTTPS/TLS) and encrypted at rest (AES-256)
  • Each customer's data is fully separated — you only ever see your own
  • Key-only administrator access; passwords are never stored in plain text
  • Firewalled, automatically patched servers with active intrusion prevention
  • Application code security-reviewed and hardened against common attacks
  • Automated backups every hour, plus a daily full server image held separately
  • Two-factor authentication available on every account

1. Where your data is stored

Your data is hosted in the United Kingdom on infrastructure certified to ISO/IEC 27001 — the international standard for information-security management. Keeping data in the UK also means it stays within UK data-protection law.

2. Encryption

In transit: every connection to the platform is protected with HTTPS/TLS encryption, so information moving between your device and our servers can't be read along the way. Any attempt to reach the app over an unencrypted (http) address is immediately redirected to the secure (https) version, and the browser is told to use the secure connection every time after that — so information isn't sent over an unprotected connection.

At rest: our backups are encrypted with AES-256, and the key that unlocks them is held only by us — a backup copy on its own can't be read without that key.

3. Your data is kept separate

The platform is multi-tenant — many agencies and housing providers use the same software — and it is built so that each customer's information is isolated. Every record is tied to the account that owns it, and the system is designed to only ever return your own data to you, so one agency cannot see, or reach, another's tenants, landlords or properties — and that separation is preserved in our backups too.

4. Secure access and sign-in

  • Administrator access is by cryptographic key only. Password logins to the server are switched off entirely, and remote "root" (full-control) access is disabled.
  • Passwords are never stored in readable form. Account passwords are protected using bcrypt one-way hashing, so even we can't see them.
  • Instant sign-out everywhere. Changing a password immediately ends any other active sessions for that account.
  • Brute-force protection. Repeated failed sign-in attempts are rate-limited, and the account is locked for a period.
  • Two-factor authentication. Accounts can be protected with a second step from an authenticator app, with single-use recovery codes for emergencies.
  • Role-based access. Within your own account, staff only see what their role allows.

5. A hardened, monitored server

  • Firewalled by default. The server refuses all incoming connections except the few that are genuinely needed (secure web traffic and protected admin access).
  • Databases are not exposed to the internet. They can only be reached by the application itself, never directly from outside.
  • Automatic security updates. The server keeps itself patched against newly discovered vulnerabilities.
  • Active intrusion prevention. Repeated malicious attempts are detected and the offending source is automatically blocked.

6. Backups and disaster recovery

Your data is backed up automatically every hour, and a full server image is taken daily by a dedicated backup service and held separately from the live server. Backups are retained so we can recover from an earlier point if ever needed, and database backups are taken cleanly and consistently so a restore brings everything back intact. A backup is also taken immediately before any release.

7. Secure development and change control

Our application code goes through an in-depth internal security review and is hardened against common web-application attacks. Reviews cover access control, tenant separation and the handling of personal data, and findings are fixed and re-tested before release. Changes to the live system are tested against an automated suite and logged, and the database is backed up immediately before each release, so a change can be reversed if it needs to be.

8. Payments

Where card payments are used, they are handled by a global PCI-DSS-certified payment provider. We never see or store your full card details.

9. Data protection and your rights

We handle personal data in line with the UK GDPR and the Data Protection Act 2018, and we're registered with the Information Commissioner's Office (ICO) under reference ZC188926. When you use Lettright to store information about your own tenants, landlords and applicants, you remain the controller of that data and we act as your data processor. Full details are in our Privacy Policy.

10. Our ongoing commitment

Security isn't a one-off task — it's something we maintain. We review our protections regularly and strengthen them as new threats emerge and best practice moves on. Your data is protected by multiple independent safeguards working together, and we treat it with the same care we'd expect for our own.

If you have any questions about security or data protection, email us at info@azurydigital.co.uk.

Lettright
ProductsPlatformPrivacyTermsSecurity
Lettright is a product of Azury Digital & Tech Solutions Ltd — a company registered in England and Wales (no. 13446812), registered office 23a The Precinct, London Road, Waterlooville PO7 7DT. ICO registration ZC188926.
© 2026 Azury Digital & Tech Solutions Ltd. All rights reserved.