Skip to content

How your complex's books are protected

The dues ledger, the resident directory and bank transactions are a complex's most sensitive records. Here's what we do inside the product to protect them.

Last updated: October 10, 2026

Accounts and access

Passwords
Passwords are stored as irreversible scrypt hashes. The plain text is never kept anywhere.
Verification
Email addresses are verified with a code at sign-up, and phones can be verified by SMS code. Linking a resident to an apartment requires phone verification or management's approval.
Roles and complex access
There are six team roles, each scoped by complex. Permissions are checked on the server; the interface only hides things. A user who follows a link to a complex outside their scope can't even see that it exists.
Support access
When the CasaX team enters an organization's dashboard to help, access is read-only and every session is logged.

Money and connections

Card details
Card numbers never reach CasaX servers. Dues and subscription payments are taken on the secure page of iyzico, PayTR or Stripe, and mobile subscriptions in the app store.
Secret keys
Keys for payment providers, BankSocket and SMS providers are stored encrypted with AES-256-GCM. Once saved, they're never shown again on any screen; only the last four characters are visible.
Payment verification
Payment results are verified with the provider's signature or a status query. The same payment can't create a second collection, and if the reported amount is lower than expected, no collection is recorded and it goes to the finance team for review.
The bank connection is read-only
The BankSocket connection reads transactions and balances; it can't transfer money. Only bank accounts mapped to a complex's account are read.

Logging and audit

Activity log
Every change to financial and resident records is written to the activity log: who made it, with which role, when, and what changed from what to what.
A ledger nothing disappears from
Financial records are never deleted. A wrong entry is voided and a reversal is created, and the auditor role can review this history read-only.
Assistant actions
CasaX Assistant only looks at records the user can see with their own permissions. Actions such as sending or saving happen only with approval, and are logged.
Browser security
Every connection uses HTTPS, and security headers such as HSTS, framing protection and content-type protection are sent on every page.

KVKK and vulnerability reporting

For a complex's records, your complex's management is the data controller, and CasaX processes those records only on management's instructions. For our own account data, we are the data controller. Both roles are explained in detail in the KVKK privacy notice, with a plain-language summary in the privacy policy.

If you think you've found a security vulnerability, send the details to info@casax.com.tr with the subject "Security report". Please don't disclose it publicly until we've confirmed and fixed it.