Skip to main content
Security & Privacy

Your data, locked to your account.

Hermit Homes is built for Malta landlords, runs on infrastructure configured for the EU, and encrypts the sensitive parts of your account before they are stored. What that does and does not protect is spelled out below.

Tenant records are encrypted at rest

Personal details belonging to you and your tenants are encrypted before they are written to our database, with AES-256-GCM — authenticated encryption, so a tampered value fails to decrypt rather than returning something wrong. Each value carries the version of the key that encrypted it, so keys can be rotated without losing older records.

  • Tenant identity and contact information
  • Free-text notes on leases, payments, and charges
  • Sensitive personal details on access requests

Non-sensitive numeric fields like rent amounts and dates remain readable by the app so totals, tax calculations and reminders keep working.

Keys live separately from the data

The key that unlocks your records is kept in a separate managed secret store — not in the database, not in our source code, and not in any log file. Keys can be rotated on a schedule without downtime.

EU-region hosting, HTTPS everywhere

Your data is hosted in Cloudflare's Western Europe (WEUR) region and encrypted at rest. Every connection to Hermit Homes is encrypted in transit. Two-factor authentication is available on every account and strongly recommended.

Your records aren't a product

Hermit Homes never sells your data, never shows ads, and never trains AI models on your records. We make money from subscriptions, not from your information. The only third parties that touch it are the ones needed to run the service — our hosting provider and our email provider — each listed, with what they receive, in the Privacy Notice.

Honest limits

We believe in telling you what encryption can and can't do. Here's the honest version:

  • Hermit Homes can still read decrypted values to render your pages, the same way every mainstream SaaS works. Encryption at rest protects the stored data; it does not put your records beyond our reach.
  • Numeric fields aren't encrypted because the whole point of a property portal is to sum, report, and remind on them. A stolen database would still reveal totals and dates, but not the tenants tied to them.
  • Your own inbox and browser are outside our control. Anything we email you ends up in your recipient's inbox as-is. Use a strong password and two-factor auth on that account too.

Questions or responsible-disclosure reports? Email [COMPANY EMAIL — REQUIRED BEFORE LAUNCH].