agentOS Block Manager is built for a regulated world — RICS codes, FCA client money rules, UK GDPR, and multi-tenant data isolation are architectural constraints, not afterthoughts. Here is exactly what we do and how we do it.
All financial data is encrypted at rest using AES-256 and transmitted over TLS 1.2 or higher. This covers every ledger entry, bank feed, service charge demand, and reserve fund record.
Each block's funds are individually ring-fenced and segregated from the agent's own money in accordance with FCA client money rules and CASS requirements. Block funds are never commingled.
All personal data is stored exclusively in UK-based data centres. This applies to primary storage, backups, and logs. UK data residency is a non-negotiable infrastructure constraint.
Five distinct roles — Principal, Property Manager, Read-Only, Leaseholder, and Freeholder/Owner — each with enforced permission boundaries. No role can access data outside its permitted scope, including your own team.
Every financial record, transaction, document, and ledger entry is encrypted before it touches disk. All network communications — including bank feeds, accounting connectors, and leaseholder portal traffic — use TLS 1.2 or higher.
Calmony accounts are individually ring-fenced per block. Management fee income is tracked as a separate financial category and never touches block client funds — required for RICS code and FCA CASS compliance.
Every compliance action — certificate uploads, inspection completions, Building Safety Act submissions — is logged with user, timestamp, and document reference. Communication logs record sender, recipients, channel, and delivery status. Neither log can be modified or deleted.
TrueLayer open banking connections are strictly read-only. The platform uses the OAuth connection to read transactions — it cannot initiate payments, move funds, or modify account data through this channel. Re-authentication is required in line with Open Banking SCA requirements (typically every 90 days). Payment initiation is a separate, separately authorised workflow using Calmony accounts only.
RICS code compliance, FCA client money separation, UK GDPR data residency, and immutable audit trails — these are not features we added. They are constraints we designed around. Join the waitlist to see it working.
Questions? Email sf-core-org-support-agentos-block-manager@saas-factory.ai
No agent can see another agent's blocks, leaseholders, accounts, or documents — at any layer of the stack. Queries, reports, and API responses are all scoped to the authenticated tenant. There is no shared view, no cross-tenant leakage.
Strict tenant scoping on every database query
Separate document storage per managing agent organisation
API responses gated to authenticated tenant context
No cross-owner financial reporting — legally distinct client money stays separate

The communication audit trail logs every message — broadcast, individual thread, automated reminder, and notice board post — with timestamp, sender, recipient list, and delivery status. The compliance audit trail separately records every compliance action. Both are immutable: no user, including a Principal, can modify or delete either log.
All personal data stays within UK-based infrastructure. Subject access requests and right-to-erasure workflows are supported. A data processing agreement is available to all organisations on the platform.
Primary storage, backups, and logs all remain within UK jurisdiction. No cross-border data transfer for personal data.
Platform supports subject access requests and right-to-erasure — subject to financial record retention obligations where the law requires data to be kept.
Every document uploaded to the block or unit document vault passes through automatic virus scanning before being stored. Uploading a replacement file creates a new version while every prior version is retained — the audit history is never overwritten.
Virus scanning on every upload via background processing
Version history with upload date and uploading user
Time-limited pre-signed download URLs — files never publicly accessible by default
Leaseholders can only access their own unit documents

A privacy notice and DPA are available to all users. Linked from the platform footer and available at /dpa and /ropa.
Block documents selectively published — agent controls visibility
