Yardi Canada · Trust Center

Yardi Canada Trust Center

Trust center

Yardi Canada maintains a public trust center documenting SOC 2 (annual), SOC 1 (biannual), SSAE 18, PCI, HIPAA, Sarbanes-Oxley, CSA STAR Level 2, and FIPS 140-2 (key management) compliance.

Real EstateCanadaProperty ManagementRentalsCommercial Real EstatePropTechMultifamilyAffordable HousingSenior LivingInvestment ManagementTenancyPaymentsMCPAI
Trust center: https://www.yardi.com/company/cloud-security/

Certifications & Compliance

SOC 2 (annual)SOC 1 (biannual)SSAE 18PCIHIPAASarbanes-OxleyCSA STAR Level 2FIPS 140-2 (key management)

Source

Trust Center

Raw ↑
generated: '2026-07-26'
method: searched
probe: false
url: https://www.yardi.com/company/cloud-security/
name: Yardi Cloud Security
summary: >-
  Yardi has no branded trust portal — trust.yardi.com does not resolve and
  /trust, /security and /compliance all 404 on www.yardi.com, which is why the
  automated trust-centre probe recorded nothing. What it does have is a single
  substantive Cloud Security page, reachable only through the company sitemap, that
  names real certifications and audit cadences. That page is the trust surface, and it
  is recorded here because the certifications on it are specific and checkable rather
  than marketing adjectives.
certifications:
  - SOC 2 (annual)
  - SOC 1 (biannual)
  - SSAE 18
  - PCI
  - HIPAA
  - Sarbanes-Oxley
  - CSA STAR Level 2
  - FIPS 140-2 (key management)
controls:
  encryption_in_transit: Automatic TLS encryption with active session management; encrypted cookies validated against the database before each request.
  encryption_at_rest: Optional AES-256 database encryption available on request; keys managed in a FIPS 140-2 compliant system.
  access_control: SSO integration, granular multi-level user/group privileges, administrator-set password complexity and expiration, automated inactivity log-off.
  network: Intrusion Prevention Systems (IPS) and multiple firewalls.
  testing: Third-party penetration tests and audits by external security vendors, described as regular and ongoing.
  physical: 15 global data centres with 24/7 server-operations monitoring, biometric screening, video surveillance and on-premises personnel.
  monitoring: 24/7 system monitoring, disaster recovery.
evidence:
  - source: https://www.yardi.com/company/cloud-security/
    status: 200
    keywords: [PCI, SSAE 18, Sarbanes-Oxley, HIPAA, SOC2, SOC1, CSA Star Level 2, FIPS140-2, AES256, penetration tests]
    quote: >-
      "Feel confident your Cloud solution complies with PCI, SSAE 18 and Sarbanes-Oxley
      regulations. Senior Living providers can rest assured with resident health data
      adhering to the latest HIPAA rules. Annual SOC2 and biannual SOC1 reports are
      provided to ensure compliance with SSAE18 and other accounting standards. The
      Yardi Coud is CSA Star Level 2 certified by the Cloud Security Alliance."
misses:
  - {url: 'https://trust.yardi.com/', status: 000, note: does not resolve}
  - {url: 'https://www.yardi.com/trust/', status: 404}
  - {url: 'https://www.yardi.com/security/', status: 404}
  - {url: 'https://www.yardi.com/company/security/', status: 404}
  - {url: 'https://www.yardi.com/security-and-compliance/', status: 404}
gaps:
  - No report request/download portal; SOC 1 and SOC 2 reports are described as "provided" but no request path is published.
  - No vulnerability disclosure policy, bug bounty or security.txt anywhere on the estate (see security/yardi-canada-vulnerability-disclosure — none found).
  - No Canadian data-residency statement, despite Voyager, Breeze, Elevate, Investor Portal, Resident Screening and EHR Interfaces each running an explicit Canada region on the status page.
  - No sub-processor list on the security page; a sub-processor page exists separately at https://www.yardi.com/about-us/legal/yardi-sub-processors.