Security
Where your client data actually lives.
You are being asked to move signed contracts and client contact details into someone else's system. Here is exactly what is in place today, and what we are still working on.
What is in place.
01Encrypted in transit and at rest. Every connection over TLS; data encrypted on disk.
02Company-scoped records, enforced at the database. Row-level security means the keys shipped in a browser cannot read another company's rows, the isolation is not just a filter in the interface.
03One control point for changes. Every write to a deal, human or automated, is stamped with who did it, so the assistant's own work carries a visible badge.
04Signature audit certificates. Every e-signature produces a sealed PDF plus a certificate recording each signer's name, role, timestamp and IP, split per side.
05Monitoring. Dependency probes every ten minutes, ninety days of uptime history, and every crash captured and alerted within thirty minutes.
06Retention. Transaction records are kept for seven years to meet real-estate record-keeping expectations. Closed files move behind an archive toggle, not into a bin.
Where the discipline lives today. Formal certifications are on our roadmap, and we will not claim one before an auditor signs it. What protects your data now is the build itself: per-brokerage isolation enforced in the database, encryption in transit and at rest, immutable signature audit trails, and the data processing agreement published on this site. If your procurement has a questionnaire, send it, we answer in writing.
Your data
We do not train general models on your content.
Your clients, contacts, deals, documents and contracts are never shared between companies or accounts, and are not used to train general-purpose AI models.
Sub-processors that touch data are published and we commit to notifying customers before that list changes.