Identity & Verification
Every participant's capabilities are tied to verification state, not self-declaration:
- Role-based onboarding: tenants/buyers, landlords/owners, agents and property professionals each complete the workflow required for their role and market.
- KYC cases: identity documents are submitted to a structured case, reviewed by authorised reviewers, and tracked through explicit statuses — approved, pending, rejected — with document-level outcomes.
- No silent approvals: a status only changes when a reviewer records a decision, and the decision is logged.
Property Verification
- Ownership / authority evidence: owners submit proof of ownership; agents submit mandates from owners.
- Document review: titles, surveys and supporting documents are reviewed against marketplace requirements for the property type and transaction before statuses update.
- Listing standards: listings failing completeness or consistency checks remain pending, with the reason visible to the lister.
Transaction Controls
- Structured records: applications, viewings, agreements, payment intents, receipts, payouts and ledger entries are linked to the transaction they belong to.
- Escrow workflows: funds held through the Platform can be frozen when a dispute is opened, and released or refunded only through recorded actions with reasons.
- Double-entry ledger: payment activity is reconciled entry by entry, so money movements can be traced.
- Transaction-linked disputes: a dispute must be attached to a recorded property, payment, agreement or application — it cannot be opened in a vacuum.
Security
- Passwords are hashed — never stored or transmitted in plain text.
- Session-based authentication with a secure, script-unreadable cookie and multi-factor authentication support.
- Role-based access control (RBAC): staff and admin capabilities are scoped per role and per permission; sensitive actions require the right permission.
- Rate limiting protects authentication and public endpoints from abuse.
- Fraud and risk monitoring flags suspicious accounts, listings and message patterns for review.
Audit & Accountability
- Significant actions — verification decisions, payment actions, dispute decisions, admin overrides — are written to an append-only audit log with who, what, when and details.
- Platform-level switches (for example disabling new disputes) are themselves recorded with their change history.
- Admin activity is attributable to named admin accounts, not shared logins.
Dispute Handling
Disputes follow a defined lifecycle — opened, under review, evidence requested, decision issued — with evidence submitted by the parties, a recorded timeline, and an appeal status. Full detail is on the Dispute Resolution page.
Data Protection
- Data collection is limited to what the Platform needs to operate (see the Privacy Policy).
- Privacy requests — access, correction, deletion and restriction — are handled through a structured workflow with identity verification of the requester.
- Identity documents are not displayed to other users; only verification statuses are shared.
Legal Requests
Valid legal requests — such as court orders or lawful authority requests — are reviewed before any data is disclosed, and disclosure is limited to what the request lawfully requires. Requests are handled through the support contact page with the subject “Legal Request”. Plain-text email is not an accepted channel for account changes.
Scope & Limitations
Livora is a marketplace and transaction-record platform. It is not a bank, escrow agent, law firm, licensed broker or conveyancer, and nothing on this page should be read as such a claim.