Key facts
| Access control | Scoped API keys with rotation; enterprise SSO and RBAC options |
| Portfolio separation | Separate keys and retrieval indexes per portfolio or property |
| Deployment | Cloud, VPC, on-prem or air-gapped per owner requirement |
| Auditability | Request, model and response logging for decision review |
| Data grounding | Embeddings and RAG are live for leases, policies and maintenance history |
| Structured output | JSON mode returns maintenance and notice records in fixed schemas |
| Models | 30+ models behind one OpenAI-compatible API |
| Endpoint roadmap | Files, batch and fine-tuning are coming soon |
TL;DR
- Separate owner, tenant and vendor data before automating any workflow.
- Scope keys per portfolio so management contracts stay isolated.
- Apply retention to chat and maintenance transcripts as lease records.
- Log requests, sources and reviewers for anything affecting a tenant.
- Keep screening and enforcement decisions with named humans.
How it works, step by step
- Inventory AI use cases across leasing, maintenance, accounting and communications.
- Classify data by tenant, owner, vendor and regulatory sensitivity.
- Choose deployment per class: cloud, VPC, on-prem or air-gapped.
- Issue per-portfolio and per-application keys with rotation and central inventory.
- Define log fields and retention: request ID, model, sources, output, reviewer decision.
- Approve a model allow-list and ground answers in current leases and policies.
- Require human review for screening, notices and enforcement actions.
Try it yourself
Open the AI data residency checklist →
Tenant, owner and lease data
Property management data spans public listings, building information, lease agreements, tenant records, owner statements and vendor contracts. Owner and tenant interests differ, and management agreements often restrict how each dataset may be used and where it may be processed.
Start with public building information and standard policies, then extend to tenant and lease content only where the management agreement permits it and the deployment keeps data inside the agreed boundary.
Keys, portfolios and least privilege
Issue a distinct API key per portfolio, property system and application. Store keys in a secrets manager, rotate on a schedule, and revoke them when a management contract ends, which happens regularly as portfolios change hands. Enterprise SSO and RBAC options keep console access aligned with staff turnover at each site and with third-party managing agents.
Never place tenant identifiers or payment details in prompts where retrieval can supply only the fields a task requires.
Residency, retention and fair-process records
Decide where processing happens and how long records live. Region selection covers many residency needs; VPC, on-prem and air-gapped deployment covers owners and jurisdictions with stricter requirements. Retention applies to prompts, outputs, logs and retrieval indexes, and lease and maintenance records follow their own schedules.
Log enough to explain a decision that affected a tenant: request ID, model and version, retrieved source identifiers, output and the human reviewer. See AI audit logs for a schema.
Model governance and human review
Keep an approved model list with evaluation evidence and re-test when versions change. Ground answers in current leases and policies with citations so staff can verify quickly. Screening, notices, fee disputes and enforcement actions stay with named humans, and the checklist should state which decisions may never be automated and who reviews exceptions in each portfolio.
Honest comparison
| Control area | Plugsky capability | Common gap | Owner |
|---|---|---|---|
| Portfolio separation | Separate keys and indexes per portfolio | One workspace for all owners | Operations |
| Identity | Scoped keys, rotation, enterprise SSO and RBAC options | Shared site credentials | IT security |
| Data boundary | Cloud, VPC, on-prem or air-gapped deployment | Tenant data path undocumented | Compliance |
| Retention | Configurable logging of requests and responses | Transcripts kept indefinitely | Records |
| Audit trail | Request, model and reviewer logging | Notices not traceable | Risk |
| Human review | Citations and structured output for staff | Automated screening decisions | Portfolio manager |
Frequently asked questions
Does using Plugsky make us compliant?
No. Compliance is your program. Plugsky provides deployable controls - scoped keys, portfolio separation, private deployment, logging - that you document and audit against your management agreements and legal obligations.
Can we keep tenant data in one region?
Yes. Region selection covers many requirements, and VPC, on-prem and air-gapped deployment keeps data inside a chosen environment or country.
What should we log?
Request IDs, model names and versions, retrieved sources, outputs and the human reviewer, retained under your policy so tenant-affecting decisions can be explained.
Can AI screen rental applications?
Retrieval and summarisation can assist staff, but screening decisions that affect applicants should remain with trained humans, with the workflow documented for fair-process review.
How do we handle maintenance transcripts?
Treat them as lease records, apply the same retention, and keep resident identifiers out of prompts where retrieval can supply only the work-order fields needed.
Is fine-tuning available for our lease templates?
Fine-tuning, files and batch endpoints are coming soon. Today, use retrieval over approved leases and policies with JSON mode for consistent output.
Where should a pilot start?
Pilot on public building information and standard policies with the free plan, validate answers and logging, then extend to tenant workflows on private deployment.