Security by design
Layered safeguards protect account, property, payment, and support workflows from unauthorised access or misuse.
Trust & Security
Property journeys depend on trust. We protect the data, decisions, and conversations that move each journey forward with layered safeguards and clear accountability.
Layered safeguards protect account, property, payment, and support workflows from unauthorised access or misuse.
PDPA-aware data handling, purpose limitation, and clear rights processes guide how personal data is managed.
Public service status, staffed reporting channels, and plain-language policies make our posture easier to inspect.
In depth
Explore the measures Homejourney applies across product, data, access, infrastructure, and incident response.
OTP verification, managed sessions, and guarded account flows reduce the risk of unauthorised access.
Rate limits and scanner blocking patterns help reduce automated abuse, credential attacks, and malicious traffic.
Sensitive workflows apply authentication, validation, and least-privilege checks before protected operations run.
Production web and app traffic uses HTTPS and modern TLS to protect data moving between users and Homejourney.
Core database, object storage, and backup services use encryption-at-rest controls provided by our infrastructure partners.
Primary data infrastructure is placed in Singapore where practical, with cross-border processing disclosed in our privacy policy.
We collect and use personal data for stated product, service, safety, and legal purposes. We do not sell personal data.
Active account data is kept while an account is open and is removed after deletion according to documented retention and legal-hold rules.
Users can request access, correction, withdrawal of consent, or deletion through our Data Protection Officer.
Row-level security policies and server-side identity checks restrict access to records a user is authorised to use.
Privileged operations require stronger authentication and narrowly scoped operator permissions.
Production credentials are separated by environment and limited to the systems and workflows that require them.
User-controlled input is validated before processing, and client-facing errors are sanitised to avoid leaking internal details.
Parameterized queries and safe output rendering reduce injection and cross-site scripting risk.
Automated tests, dependency checks, static analysis, and protected delivery gates review changes before production release.
Homejourney uses established cloud, database, and deployment providers with independently maintained security programs.
Operational monitoring, encrypted backups, and documented recovery workflows support detection and service restoration.
The public status page communicates broad service health without exposing private customer or security details.
Stripe handles payment card processing, so raw card details do not pass through or remain on Homejourney servers.
Data is shared only with providers needed to deliver and protect a requested service, subject to contractual safeguards.
Provider certifications describe those providers. Homejourney does not present a supplier's certification as its own.
Suspected security events are assessed, contained, investigated, and remediated through owned response workflows.
Where a breach is notifiable, Homejourney follows PDPA notification duties, including the three-calendar-day PDPC timeline after that determination.
Researchers and users can report suspected vulnerabilities directly to the technical team for private review.
If you believe you found a security issue, email our technical team with the affected surface, reproduction steps, and potential impact. Please avoid destructive testing or including personal data.
Privacy and data-rights requests: [email protected]. Homejourney Pte. Ltd. UEN: 202406236N.