agentOS Block Manager
BlogContactFAQFeaturesHow it worksIntegrationsSecurityUse cases
Get started
agentOS Block ManagerGet started
agentOS Block Manager
HomeBlogContactFAQFeaturesHow it worksIntegrationsSecurityUse cases
Get started
agentOS Block Manager
BlogContactFAQFeaturesHow it worksIntegrationsSecurityUse cases
TermsPrivacyData Processing

© 2026 agentOS Block Manager

SECURITY & COMPLIANCE

Client money handled with the rigour the law demands

agentOS Block Manager is built for a regulated world — RICS codes, FCA client money rules, UK GDPR, and multi-tenant data isolation are architectural constraints, not afterthoughts. Here is exactly what we do and how we do it.

Encryption in transit and at rest

All financial data is encrypted at rest using AES-256 and transmitted over TLS 1.2 or higher. This covers every ledger entry, bank feed, service charge demand, and reserve fund record.

FCA-aligned client money separation

Each block's funds are individually ring-fenced and segregated from the agent's own money in accordance with FCA client money rules and CASS requirements. Block funds are never commingled.

UK data residency — hard requirement

All personal data is stored exclusively in UK-based data centres. This applies to primary storage, backups, and logs. UK data residency is a non-negotiable infrastructure constraint.

[ HOW IT WORKS / SECURITY LAYERS ]

Five layers between your data and the wrong hands

  1. LAYER 01 — IDENTITY

    Role-based access control

    Five distinct roles — Principal, Property Manager, Read-Only, Leaseholder, and Freeholder/Owner — each with enforced permission boundaries. No role can access data outside its permitted scope, including your own team.

  2. LAYER 02 — ENCRYPTION

    AES-256 at rest, TLS 1.2+ in transit

    Every financial record, transaction, document, and ledger entry is encrypted before it touches disk. All network communications — including bank feeds, accounting connectors, and leaseholder portal traffic — use TLS 1.2 or higher.

  3. LAYER 03 — CLIENT MONEY

    Ring-fenced accounts per block

    Calmony accounts are individually ring-fenced per block. Management fee income is tracked as a separate financial category and never touches block client funds — required for RICS code and FCA CASS compliance.

  4. LAYER 04 — AUDIT

    Immutable compliance and communication logs

    Every compliance action — certificate uploads, inspection completions, Building Safety Act submissions — is logged with user, timestamp, and document reference. Communication logs record sender, recipients, channel, and delivery status. Neither log can be modified or deleted.

console
0.1sRBAC: evaluating role → PropertyManager
0.2sscope: blocks[assigned] only
0.3saccess granted — 3 blocks in scope
0.1sledger write: encrypting payload AES-256
0.2sTLS 1.3 verified on outbound feed
0.3srecord committed — encrypted at rest
0.1stransfer request: block-12 → agent account
0.2sBLOCKED: client money isolation rule
0.3sformal payment workflow required
0.1scompliance.log → appending entry #4821
0.2simmutable: write-once confirmed
0.3saudit trail intact — ARMA/RICS ready
OPEN BANKING

Read-only bank connections — no payment access through open banking

TrueLayer open banking connections are strictly read-only. The platform uses the OAuth connection to read transactions — it cannot initiate payments, move funds, or modify account data through this channel. Re-authentication is required in line with Open Banking SCA requirements (typically every 90 days). Payment initiation is a separate, separately authorised workflow using Calmony accounts only.

[ READY WHEN YOU ARE ]

Built for the regulation you already live under

RICS code compliance, FCA client money separation, UK GDPR data residency, and immutable audit trails — these are not features we added. They are constraints we designed around. Join the waitlist to see it working.

Questions? Email sf-core-org-support-agentos-block-manager@saas-factory.ai

MULTI-TENANT ISOLATION

Every managing agent operates in a completely isolated data environment

No agent can see another agent's blocks, leaseholders, accounts, or documents — at any layer of the stack. Queries, reports, and API responses are all scoped to the authenticated tenant. There is no shared view, no cross-tenant leakage.

  • Strict tenant scoping on every database query

  • Separate document storage per managing agent organisation

  • API responses gated to authenticated tenant context

  • No cross-owner financial reporting — legally distinct client money stays separate

agentOS Block Manager activity and audit trail view
AUDIT TRAILS

Two separate audit trails — one for communications, one for compliance

The communication audit trail logs every message — broadcast, individual thread, automated reminder, and notice board post — with timestamp, sender, recipient list, and delivery status. The compliance audit trail separately records every compliance action. Both are immutable: no user, including a Principal, can modify or delete either log.

UK GDPR

Personal data processed under UK GDPR — with the controls to prove it

All personal data stays within UK-based infrastructure. Subject access requests and right-to-erasure workflows are supported. A data processing agreement is available to all organisations on the platform.

UK data centres only

Primary storage, backups, and logs all remain within UK jurisdiction. No cross-border data transfer for personal data.

Subject access & erasure

Platform supports subject access requests and right-to-erasure — subject to financial record retention obligations where the law requires data to be kept.

DOCUMENT SECURITY

Version-controlled documents with virus scanning on every upload

Every document uploaded to the block or unit document vault passes through automatic virus scanning before being stored. Uploading a replacement file creates a new version while every prior version is retained — the audit history is never overwritten.

  • Virus scanning on every upload via background processing

  • Version history with upload date and uploading user

  • Time-limited pre-signed download URLs — files never publicly accessible by default

  • Leaseholders can only access their own unit documents

FREQUENTLY ASKED

Security questions, plainly answered

agentOS Block Manager dashboard — scoped to a single managing agent
These trails exist as evidence — in arrears proceedings, ARMA inspections, and RICS audits, a timestamped record of what was sent and when is not a nice-to-have. It is the defence.

Data processing agreement

A privacy notice and DPA are available to all users. Linked from the platform footer and available at /dpa and /ropa.

  • Block documents selectively published — agent controls visibility

  • agentOS Block Manager agency settings and document controls
    It does more than show a balance. The engine runs a year-by-year projection across up to 20 years, starting from your live reserve fund balance, adding monthly contributions with an inflation uplift you set per block, and deducting each forecast replacement event in the year it falls due. When any future year shows a shortfall, an alert fires automatically on the block dashboard and your agent-level dashboard, naming the specific assets driving the gap and the exact shortfall amount. You can then run scenario models — adjusting contributions, replacement dates, or inflation assumptions — without clearing the alert until the gap is genuinely resolved. It is connected in real time to the asset register, so any condition rating change or cost update on an asset immediately ripples through the projection.
    The platform connects to Xero (UK edition), QuickBooks Online (UK edition), and Sage Online, all via OAuth 2.0 authentication. These connectors pull the P&L report directly from your existing accounting system and display it inside Block Manager — they are not ledger sources and they do not replace your accountant's workflow. For blocks where you are not using an external accounting package, the platform builds the P&L from its own unified ledger, which consolidates transactions from TrueLayer open banking, Calmony, and manual CSV imports into a single view. The agent-facing P&L interface looks the same regardless of source. Sage requires an additional nominal code mapping step to align its chart of accounts to Block Manager's reporting categories.
    Each block's funds are ring-fenced at the account level. Calmony accounts opened through the platform are individually ring-fenced as client money, kept entirely separate from other blocks' funds and from the agent's own money, in compliance with RICS client money protection requirements and FCA client money rules where applicable. Management fee income is tracked as a distinct transaction type and nominal code category and is never reported alongside block client funds in any ledger or P&L output. The platform enforces this separation as a hard rule — no cross-block fund transfers are permitted except through a formal payment request workflow, and portfolio reporting is always scoped to a single owner's blocks, because different owners' funds are legally distinct client money.
    Every leaseholder has an individual ledger recording every demand raised and every payment received, producing a live running balance at all times. Arrears are recalculated continuously as payments arrive, including partial payments and payment plan instalments. The arrears dashboard gives each unit a RAG status with days overdue and total outstanding, and the portfolio view surfaces your top blocks by arrears so nothing slips unnoticed. Payments imported via TrueLayer or Calmony are auto-matched to open demands by reference and amount, reducing manual reconciliation work. Unmatched payments go to a suspense queue flagged for your review rather than being silently ignored. Service charge demands are dispatched as branded PDF letters with a QR code payment reference, and the communications centre lets you target bulk messages specifically at leaseholders in arrears.
    Yes. The Section 20 tracker manages the full three-stage statutory process under the Landlord and Tenant Act 1985 for contracts exceeding £250 per unit: Notice of Intention, Notice of Proposal with contractor nominations and estimates, and Award Notice. Each stage records dispatch dates, observation period deadlines, and leaseholder responses. The platform generates compliant notice documents as PDFs and sends an automated reminder five days before each observation period closes so a missed deadline is not a realistic risk. A status timeline shows the current stage, days elapsed, and next deadline at a glance. All notices and leaseholder responses are stored with their dispatch dates for audit purposes.
    All financial data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. The platform is built on a strict multi-tenant architecture — each managing agent's account is a completely isolated data environment, with no possibility of cross-tenant data access at any layer. All personal data is processed in accordance with UK GDPR, and all data is stored exclusively in UK-based data centres, including backups and logging — there is no offshore data residency. The platform supports subject access requests and right to erasure (subject to financial record retention obligations). Documents uploaded to the platform are virus-scanned automatically on upload. Role-based access control with five defined roles — from Principal down to Leaseholder portal access — means every user sees only what their role permits.