Last updated: 2026-07-09 Version: 1.0
GoProp is a software service operated and offered by AGGREGATIVE VALUE SOLUTIONS AGGVAL LLC, a limited liability company formed in the State of New Mexico, United States (“AGGVAL”). Unless the context indicates otherwise, references in this document to “GoProp”, “we”, “us” or “our” refer to AGGVAL.
This Policy describes the general security practices applicable to GoProp.
GoProp is a software-as-a-service platform for the operational administration of condominiums, homeowners associations, communities, buildings, residential complexes or similar organizations.
1. General principle
GoProp aims to apply reasonable technical and organizational measures to protect the confidentiality, integrity and availability of the platform and the data processed on it.
No computer system is completely secure. Security also depends on responsible use by the Client and Users.
2. Access security
GoProp may implement access controls to limit the information and features available based on the User's role.
The Client is responsible for:
- creating users only when necessary;
- assigning appropriate roles;
- removing access that is no longer needed;
- avoiding shared accounts;
- periodically reviewing active users;
- protecting credentials and devices.
3. Authentication and sessions
GoProp may use passwords, JWT tokens, technical cookies, local storage, sessions or other authentication mechanisms.
Users must keep their credentials confidential and notify us if they suspect unauthorized access.
GoProp may close sessions, invalidate tokens, suspend accounts or apply restrictions when it detects suspicious activity or a security risk.
4. Data separation by organization
GoProp aims to apply logical data separation by Organization, so that users only access information corresponding to their role and permissions.
This logical separation relies on authorization rules, application-level controls and good development practices.
5. Encryption in transit
GoProp will use secure HTTPS/TLS connections to protect the transmission of data between the User's browser and the platform.
The Client should avoid accessing GoProp from insecure networks, compromised devices or outdated browsers.
6. Backups
GoProp will attempt to generate at least one backup of production data every thirty days, in accordance with the Service Level Agreement and the Data Retention and Deletion Policy.
Backups are a continuity and recovery measure, not an absolute guarantee of complete or selective restoration.
7. Monitoring and logging
GoProp may maintain technical logs, authentication records, error events, operational audit trails and security data to:
- diagnose issues;
- investigate incidents;
- prevent fraud or abuse;
- improve stability;
- protect data and users;
- comply with legal or contractual obligations.
8. Vulnerability management
GoProp may fix vulnerabilities, apply updates, modify configurations or restrict features when necessary to protect the service.
Some fixes may require urgent maintenance without prior notice.
9. External providers
GoProp may depend on external providers for hosting, storage, email, security, analytics, support, payments or other technical services.
We will try to use reasonably trustworthy providers and limit third-party access to what is necessary to provide the service.
However, GoProp does not fully control the infrastructure, policies or incidents of external providers.
10. Client responsibility
The Client and its Users must apply good security practices, including:
- using strong passwords;
- not sharing accounts;
- logging out on shared devices;
- keeping devices and browsers up to date;
- avoiding insecure networks;
- reviewing permissions;
- reporting suspicious access;
- verifying information before uploading documents or sensitive data;
- keeping their own copies of critical records when necessary.
11. Content and uploaded files
The Client is responsible for the files, documents, images and data it uploads to GoProp.
It must not upload malware, dangerous files, illegal content, excessive data or information it is not authorized to process.
GoProp may block, remove or restrict files that pose a technical, legal or security risk.
12. Reporting incidents or vulnerabilities
If a User, Client or third party identifies a possible security incident or vulnerability, they must report it through the official channels published by GoProp.
The report should include:
- description of the issue;
- steps to reproduce it, if applicable;
- affected URL or feature;
- approximate date and time;
- potential impact;
- screenshots or evidence, if applicable.
Vulnerabilities must not be exploited, publicly disclosed, used to extract data, used to interrupt the service, or used to access third-party information while investigating them.
13. Incident notification
If GoProp identifies a security incident that materially affects Client data, it will use reasonable efforts to notify the Client without undue delay after becoming reasonably aware of the incident.
The notification may include available information about the incident, measures taken and recommendations.
14. Limitations
Security measures may vary depending on the product stage, the contracted plan, available infrastructure, country, providers used and GoProp's technical evolution.
This Policy does not guarantee that the service is free of vulnerabilities, errors, attacks, data loss or interruptions.
15. Changes to this Policy
GoProp may update this Policy to reflect technical, legal or operational changes. The current version will be published together with its update date.
16. Contact
For questions or reports related to security, the Client or User may contact us through the official channels published on the website or within the platform.