ADDA
ADDA TRUST CENTER

Protecting your data, privacy and trust

Community and rental software holds the most sensitive information a building has — what people own, what they owe, who comes and goes. Here's exactly how we protect it, including the things we haven't finished yet.

ISO/IEC 27001:2022AWS (ISO 27017 / 27701 / 27018)DPDP ActPCI-DSSMonthly VAPTIndependently validated
Why it matters

The most sensitive data in a building lives here

Your platform holds owners' personal details, payment history, and a log of who enters the community and when. Protecting it isn't a feature — it's the baseline for being trusted with a community at all.

That's why security at ADDA isn't a page we wrote once. It's monthly testing, annual third-party audits, encrypted backups, tightly controlled access, and independent certification — reviewed continuously, not set and forgotten.

Foundations

Built on the highest standards of security

🛡️

Industry-leading security protocols

Layered protection across the platform, reviewed continuously.

🔒

End-to-end encryption

Data encrypted both in transit and at rest, so it's unreadable if intercepted.

Certified for global compliance

Independently audited against internationally recognised standards, not self-declared.

Continuous practices

Security isn't a one-time badge — it's a routine

🔎

Frequent VAPT & audits

  • Internal Vulnerability Assessments & Penetration Testing at least once a month
  • Annual third-party audits by top cybersecurity experts
  • Findings tracked to closure, not filed away
🔑

Controlled access & credential protection

  • Encrypted password management across all systems
  • Data access granted only to authorised, security-trained personnel
  • Strict internal protocols governing who can see what, and when
💾

Backup & disaster recovery

  • Daily backups for critical functions like payments
  • Monthly backups for non-critical operations
  • Encrypted backups in Amazon Glacier, with a maximum 24-hour Recovery Point Objective
Hosting

Hosted on AWS — enterprise-grade infrastructure

Your platform runs on the same infrastructure trusted by the world's largest enterprises.

  • ISO 27017, ISO 27701 and ISO 27018 compliant — with built-in DDoS protection, encryption at rest and in transit, GuardDuty threat detection and CloudTrail logging
  • 24×7 infrastructure monitoring and auto-scaling architecture for performance and uptime
  • Resilient by design — no single point of failure for critical services

Need to run on your own terms? ADDA also supports private cloud and on-premise deployment for organisations whose IT policy or client contracts require it — with the same security posture across every option. Hosting & Deployment

AWS Partner
Payments

Secure payment processing

Over AED 578M has been paid through ADDA — every transaction handled to banking-grade standards.

PCI-DSS compliant gateways — Razorpay, Cashfree, Stripe, PayFort, Braintree

Payment data encrypted and transmitted only through secure, validated channels

ADDA never stores raw card data — it stays with the certified gateway

Certifications

Independently certified — not self-declared

ISO/IEC 27001:2022

ISO/IEC 27001:2022

For implementing and maintaining an internationally recognised Information Security Management System (ISMS).

Issued 17 Jun 2025 · Valid till 16 Jun 2028 · Cert No. 25RN06EV · available on request

Digital Personal Data Protection (DPDP) Act

Digital Personal Data Protection (DPDP) Act

DPDP-certified and aligned with the DPDP Act, supported by documented policies and processes.

Issued 10 Jan 2026 · Valid till 09 Jan 2027 · Cert No. TT2026003D

SOC 2 — aligned, certification in progress

Our security practices are aligned with SOC 2 requirements; the formal certification is not yet complete. We'd rather state that plainly than let a badge imply otherwise. If SOC 2 is a hard requirement for your organisation, tell us early and we'll be straight about where we stand.

Privacy

Your data is used to run your community — nothing else

We have no other business. No conflict of Interests. We don't sell or share your data — not with advertisers, not with anyone

The app is ad-free — no advertising means no incentive to mine resident data

Aligned with the DPDP Act — documented policies for how personal data is collected, stored and handled

Clear data ownership — your community's data is yours to export, and yours alone to control

No conflict

A software company with no reason to touch your data

Where your data sits matters — and so does who holds it.

ADDA is a pure software company. We build community, rental and visitor management software, and nothing else. There's no brokerage arm, no real-estate sales business, no part of the company that profits from the buildings whose data we hold.

For a committee deciding where its owners' financial and personal information will live, that absence of conflict is often the quiet deciding factor — because your data is never an asset to a business that also trades the very property it describes.

Pure software.

No data-selling business model.

No conflict of interest.

Access control

Everyone sees only what they should

A community has many hands on the system — and not all of them should see the same things.

Role-based access

Your accountant, a community manager, a security supervisor and a committee member each see only what their role permits.

Read-only access where needed

Committees or auditors can view live budgets, collections and reports, as per need.

Full audit logs

Every action recorded, timestamped and attributed, so nothing is untraceable.

Got Questions?

Frequently Asked Questions

Is ADDA ISO 27001 certified?

Yes — ISO/IEC 27001:2022, independently audited. The certificate (No. 25RN06EV, valid to June 2028) is available on request.

Where is our data hosted, and can we keep it on our own infrastructure?

ADDA runs on AWS with ISO 27017/27701/27018 compliance. For organisations that require it, we also offer private cloud and on-premise deployment.

How often is the platform security-tested?

Vulnerability assessments and penetration testing run at least monthly, with annual third-party audits by external cybersecurity experts.

Are you SOC 2 certified?

Our practices are aligned with SOC 2 requirements, but the formal certification isn't yet complete. We'll always be straight about this — if it's a hard requirement for you, tell us early.

Do you sell or share resident data?

No. We don't sell or share your data, and the app is ad-free — there's no advertising business creating an incentive to.

What happens to our data if we leave?

Your data is yours. It's exportable, and it remains under your control throughout.

Contact

Questions about data security or privacy?

Reach our Data Protection team in your region — we typically respond within one business day.

ISO/IEC 27001:2022 ISO 27017 / 27701 / 27018 (AWS) DPDP Act certified PCI-DSS gateways Monthly VAPT Ad-free No data selling