Everything About People Counting Solutions & Features

leasing automation tender — Security Requirements for Leasing Automation Tender | Vemco Group

Written by Admin | Jul 26, 2026 10:21:39 AM

The most expensive mistake in a leasing automation tender rarely shows up on the pricing sheet. It surfaces eighteen months later, when a tenant's lawyer asks who has access to the visitor data feeding their turnover-rent calculation, and nobody in the room can answer. Security requirements are usually the last section teams write and the first section that gets exploited during vendor negotiations. If you treat them as boilerplate, you inherit the vendor's risk posture by default.

Why security belongs at the top of the evaluation, not the bottom

Leasing automation touches three data categories that carry very different obligations: commercial data (rent, lease terms, tenant financials), operational data (footfall, dwell, conversion), and personal data if any camera-based system is involved. A tender that lumps these together produces vague requirements and vague answers. Separate them. The commercial layer demands strict role-based access and audit trails because it drives money. The operational layer demands data-residency clarity and retention limits. The personal-data question determines whether GDPR applies to your counting method at all.

A practical distinction worth writing into the tender: sensor-agnostic counting platforms that do not process identifiable images sit outside most personal-data scope, which shortens your DPIA and reduces tenant objection. Vemco has run device-independent counting since 2005 across 2000+ customers and more than 85 million counts per day, and the anonymous nature of that data changes the compliance conversation before it starts. Ask each bidder to state explicitly, in writing, whether their method captures anything a data-protection authority would classify as personal.

The certifications that actually mean something

Certifications are easy to claim and hard to verify, so require evidence, not logos. Two carry weight for this category:

  • ISO 27001 — demonstrates a managed information-security system, not a one-off audit. Ask for the certificate number and the Statement of Applicability so you can see which controls are in scope.
  • SOC 2 Type II — the Type II distinction matters. Type I describes controls on paper; Type II proves they operated over a period. Request the report under NDA and read the exceptions section, which is where the real information lives.

Score a vendor who says "certification in progress" honestly against one who says "certified" and cannot produce a current attestation. The second answer is the warning sign.

Hosting, residency, and the private-cloud clause

Property owners with tenants across multiple jurisdictions cannot accept a single hosting answer. Your tender should ask where data is stored, where it is processed, and where support staff access it from — three separate questions that often have three separate answers. A platform offering both hosted and private-cloud deployment gives you room to match the arrangement to the sensitivity of the portfolio. High-profile assets or public-sector tenants may justify private cloud; a standard retail park may not need it. Write both options into the requirement and let cost follow the risk, rather than paying for isolation you don't need across every site.

Also specify integration security. Leasing automation only pays off when data moves into POS, BI, ERP, or CRM systems — Vemco handles this through VemFusion — so the tender must address how those connections are authenticated, encrypted in transit, and logged. An integration layer is an attack surface, and it is the part most tenders forget to secure.

Data accuracy is a security requirement too

This surprises procurement teams, but if leasing decisions or turnover-rent clauses depend on footfall figures, the integrity of those figures is a governance issue. A vendor who claims a flat "99% accuracy" with no conditions attached is selling you a number they cannot defend when a tenant disputes it. Insist on a contractual accuracy floor instead. Vemco commits to a contractual minimum of 96%, with 98–99% typical when lighting, store layout, and visitor behaviour allow. That distinction — a guaranteed minimum versus a marketing figure — is exactly what a tender should reward, because it survives the moment a tenant challenges the data in front of a mediator.

SLAs, incident response, and the questions bidders hope you skip

Write the service-level agreement into the tender as scored, weighted criteria rather than a post-award afterthought. At minimum, require:

  • A defined breach-notification window, in hours, with the contractual penalty for missing it.
  • Named support tiers and escalation paths — who you call at 22:00 when a store's feed drops during a peak trading week.
  • Data-portability and deletion terms at contract exit, so you are not held hostage by a proprietary format.
  • Sub-processor disclosure — the full chain, because a vendor operating across 95+ countries will use them, and you need to know who and where.

One observation from implementations that rarely appears in vendor documentation: the biggest security gap is almost never the platform. It is the offboarding of your own staff. When a leasing manager leaves, their platform access often lingers for weeks because nobody owns the deprovisioning step. Require the vendor to support automated access reviews and demand your own internal process alongside it. A perfect vendor SLA cannot fix an internal access list that nobody prunes.

Verify the references, especially at your scale

Ask for reference customers operating at a comparable scale — single store to enterprise portfolios behave differently, and a vendor comfortable at one end may struggle at the other. When you call those references, skip the satisfaction question. Ask instead how the vendor handled their last incident, their last data-subject request, and their last contract renewal. Those three answers tell you more about security maturity than any capability statement.

If you are drafting a leasing automation tender and want your security section to hold up under legal and tenant scrutiny, talk to the Vemco team about contractual accuracy floors, deployment options, and the compliance evidence your evaluation should require.