Security & Network Requirements
For your IT, security, and network teams.
What this site is
PropertyDynamix is a legitimate business-to-business SaaS application that provides real-estate pricing intelligence for property developers in Dubai and Abu Dhabi. It hosts no adult, gambling, or otherwise risky content. If your secure web gateway (for example Zscaler, Palo Alto, Symantec, Forcepoint, Fortinet) blocks the site or opens it in read-only / browser-isolation mode, please categorize propdynamix.com as Business / Professional Services and exempt it from isolation.
Domains to allow-list
Permit these so the application works end to end. All are reputable Google/Firebase or PropertyDynamix endpoints.
| Domain | Purpose |
|---|---|
| propdynamix.com, www.propdynamix.com | The application and marketing site |
| *.web.app, *.firebaseapp.com | App hosting and sign-in (Firebase) |
| identitytoolkit.googleapis.com, securetoken.googleapis.com | Authentication (Firebase Auth) |
| firestore.googleapis.com, *.firebaseio.com | Application database (Firestore) |
| *.run.app | Market-data API (DLD/ADREC) and the AI assistant gateway (Google Cloud Run) |
| *.cloudfunctions.net | Server-side functions |
| maps.googleapis.com, maps.gstatic.com | Maps |
| fonts.googleapis.com, fonts.gstatic.com | Web fonts |
| firebasestorage.googleapis.com | File/image storage |
Security posture
TLS 1.2/1.3 only, with HSTS (includeSubDomains, preload). All traffic is HTTPS.
A strict CSP is enforced (no unsafe-inline scripts), alongside X-Content-Type-Options, frame-ancestors, Referrer-Policy and Permissions-Policy.
The client bundle is scanned in CI for hardcoded secrets; service-role keys never reach the browser. Backend functions re-verify authorization server-side.
Role-based access with an admin approval workflow, append-only audit logs, and session revocation controls.
