Security at RealtyTechAI

The product includes practical safeguards for authentication, tenant isolation, integrations, and messaging. Your hosting and provider configuration remain part of the security boundary.

Transport Security

Production deployments should terminate HTTPS at a trusted proxy or hosting platform.

Tenant Isolation

API access is scoped by tenant and protected with server-side authorization checks.

Webhook Verification

Twilio webhook signatures are validated before inbound messages are processed.

Role Controls

Owner, admin, transaction-coordinator, agent, and read-only roles limit sensitive actions.

Credential Handling

Integration credentials are stored encrypted and are not exposed through application responses.

Abuse Controls

Authentication and public intake endpoints include request validation and rate limits.

Our Security Practices

Infrastructure Security

Production operators should use managed PostgreSQL, HTTPS, restricted network access, backups, and monitoring appropriate to their risk profile. These controls are deployment responsibilities.

Data Protection

Tenant identifiers are enforced in service queries, integration secrets are encrypted before storage, and sensitive values are excluded from normal API responses and logs.

Authentication & Access

The application uses signed, revocable sessions in HttpOnly cookies, verified email accounts, strong password requirements, and server-side role checks. MFA and SSO are not currently included.

Compliance

RealtyTechAI does not currently claim a third-party security certification. Customers are responsible for assessing their own legal, privacy, retention, consent, and messaging obligations.

Incident Response

Operators should configure logs, alerts, backups, key rotation, and an incident-response process before handling production data.

Vulnerability Disclosure

If you discover a security issue, use the contact page and avoid including live credentials or customer data in the initial report.